logo

Shai Hulud 2.0 Campaign

ID: 8f797fba-2f2a-5770-8cd3-43815c978e90

STIX ID: report--8f797fba-2f2a-5770-8cd3-43815c978e90

Feed Name: Detect FYI

Threat Score
85/100

Date Published: 2026-01-12

Date Updated: 2026-04-19

Author: SIMKRA

...
...

Shai-Hulud 2.0 is a large-scale npm supply-chain campaign that inserted malicious preinstall scripts (e.g., setup_bun.js → bun_environment.js) into packages to ensure a Bun runtime, download a GitHub Actions runner named SHA1HULUD as a per-host C2 repository, and run tools like TruffleHog to locate and exfiltrate cloud and developer credentials; the operation targeted developer workstations, CI/CD pipelines, and cloud workloads. The report provides technical walkthroughs, hunting queries for process/network/file telemetry, MITRE mapping, IOCs (strings, filenames, behaviors), and defensive recommendations such as restricting runner tokens, monitoring npm registry activity, protecting GCP credentials, and blocking unnecessary Bun usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.