Malware.View on attack.mitre.org
Shai-Hulud is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM packages. It exploits CI/CD pipeline dependencies to propagate to victims and poisons the supply chain by publishing malicious packages. Once inside a victim environment, Shai-Hulud steals credentials and access tokens from compromised repository accounts and exfiltrates them to attacker-controlled servers via encoded GitHub Actions workflows.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes. |
| T1036.005 Match Legitimate Resource Name or Location |
Shai-Hulud has masqueraded as a legitimate Bun installer. |
| T1036.009 Break Process Trees |
Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally. |
| T1041 Exfiltration Over C2 Channel |
Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL. |
| T1059.001 PowerShell |
Shai-Hulud has utilized PowerShell `Invoke-WebRequest` to download and install the malicious payload. |
| T1059.004 Unix Shell |
Shai-Hulud has utilized Linux shell commands to modify configuration files. |
| T1059.007 JavaScript |
Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js. |
| T1071.001 Web Protocols |
Shai-Hulud has utilized curl to install Bun over HTTPS. |
| T1078.004 Cloud Accounts |
Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories. |
| T1082 System Information Discovery |
Shai-Hulud has gathered victim system information. |
| T1098 Account Manipulation |
Shai-Hulud has modified GitHub account settings for private repositories and changed them to public. |
| T1105 Ingress Tool Transfer |
Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data. |
| T1119 Automated Collection |
Shai-Hulud has the ability to automatically collect host data, secrets, system information, and endpoints. |
| T1195.001 Compromise Software Dependencies and Development Tools |
Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages. |
| T1213.003 Code Repositories |
Shai-Hulud has downloaded existing packages from code repositories and extracted data stored within them. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.