Shai-Hulud rebuilt as a standalone stealer
ID: 79d23d25-2973-599d-8f4d-76e7a64df5d6
STIX ID: report--79d23d25-2973-599d-8f4d-76e7a64df5d6
Feed Name: Bitbison Blog
This report describes a campaign that delivered a new standalone Shai-Hulud credential-stealing worm (compiled with Bun) via React2Shell RCE on Next.js servers; the operator also deployed an SSH lateral-worm and persistent access (attacker SSH keys and Global Socket). The standalone binary collects wide-ranging credentials (GitHub, AWS, Kubernetes, Vault, CI runner secrets), propagates through GitHub repositories and npm packages, and exfiltrates results to an attacker-controlled collector; the report provides IOCs, build artifact details, and hunting guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
