Shai Hulud v2 Exploits GitHub Actions Workflows as Attack Vector to Steal Secrets
ID: b6e56b9e-fdcc-59ac-b8f6-b0869e670100
STIX ID: report--b6e56b9e-fdcc-59ac-b8f6-b0869e670100
Feed Name: cybersecurityNews.com
A sophisticated supply-chain malware campaign called “Shai Hulud v2” has infected 834 npm and Maven packages by exploiting GitHub Actions workflows (pull_request_target), installing a Bun-based two-stage loader (setupbun.js → bunenvironment.js) to harvest CI and cloud credentials (GITHUB_TOKEN, NPM_TOKEN, AWS keys), scan repositories with TruffleHog, exfiltrate encoded secrets to attacker-created GitHub repos, republish compromised packages, and persist via a GitHub-searchable beacon phrase (“Sha1-Hulud The Second Coming”); the campaign has impacted major projects and can escalate privileges or wipe systems when propagation fails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
