Stories from the SOC: The second coming of Shai Hulud
ID: 2f36fcf5-aa7f-5a38-86a1-ee81b4b4f718
STIX ID: report--2f36fcf5-aa7f-5a38-86a1-ee81b4b4f718
Feed Name: Expel Blog
This report details "Shai Hulud: The Second Coming," a large-scale NPM supply-chain malware campaign that executes via preinstall scripts to install a Bun-based payload which harvests cloud, registry, and VCS credentials (including via TruffleHog), exfiltrates stolen secrets to attacker-controlled public GitHub repositories, registers persistent self-hosted GitHub Actions runners for backdoor access, and self-propagates by publishing compromised package versions; the report includes indicators of compromise, observed scope (tens of thousands of repositories and hundreds of packages), and remediation guidance such as credential rotation, package cleanup, and CI hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
