logo

Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets

ID: b6e56b9e-fdcc-59ac-b8f6-b0869e670100

STIX ID: report--b6e56b9e-fdcc-59ac-b8f6-b0869e670100

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-11-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated supply-chain malware campaign called “Shai Hulud v2” has infected 834 npm and Maven packages by exploiting GitHub Actions workflows (pull_request_target), installing a Bun-based two-stage loader (setupbun.js → bunenvironment.js) to harvest CI and cloud credentials (GITHUB_TOKEN, NPM_TOKEN, AWS keys), scan repositories with TruffleHog, exfiltrate encoded secrets to attacker-created GitHub repos, republish compromised packages, and persist via a GitHub-searchable beacon phrase (“Sha1-Hulud The Second Coming”); the campaign has impacted major projects and can escalate privileges or wipe systems when propagation fails.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.