Defending Against Sha1-Hulud: The Second Coming
ID: 29fc72d2-d13a-52a0-8f5f-97fe2b3eeb65
STIX ID: report--29fc72d2-d13a-52a0-8f5f-97fe2b3eeb65
Feed Name: SentinelOne Blog
**Shai-Hulud Worm 2.0 — SentinelOne Wayfinder Flash Report (25 Nov 2025):** This report describes an active NPM supply-chain campaign that executes during the preinstall phase to deploy an obfuscated JavaScript payload (bun_environment.js), harvest AWS/GCP/Azure and development secrets (via Trufflehog), and persist by auto-registering self-hosted GitHub Actions runners and writing malicious workflow/discussion entries; it includes IOCs, detection rules, hunting queries, and immediate remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
