Merav Bar, Rami McCarthy, Barak Sharoni. (2025, September 16). Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware. Retrieved April 9, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareShai-Hulud | Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes. |
| T1041 Exfiltration Over C2 Channel |
MalwareShai-Hulud | Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL. |
| T1059.007 JavaScript |
MalwareShai-Hulud | Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js. |
| T1078.004 Cloud Accounts |
MalwareShai-Hulud | Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories. |
| T1098 Account Manipulation |
MalwareShai-Hulud | Shai-Hulud has modified GitHub account settings for private repositories and changed them to public. |
| T1105 Ingress Tool Transfer |
MalwareShai-Hulud | Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data. |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareShai-Hulud | Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages. |
| T1528 Steal Application Access Token |
MalwareShai-Hulud | Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories. |
| T1546.016 Installer Packages |
MalwareShai-Hulud | Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`. |
| T1567.001 Exfiltration to Code Repository |
MalwareShai-Hulud | Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories. |
| T1567.004 Exfiltration Over Webhook |
MalwareShai-Hulud | Shai-Hulud has exfiltrated repository secrets to `webhook[.]site`. |
| T1608.001 Upload Malware |
MalwareShai-Hulud | Shai-Hulud has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts. Shai-Hulud has also modified packages within compromised accounts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.