logo

Defending Against Sha1-Hulud: The Second Coming

ID: 29fc72d2-d13a-52a0-8f5f-97fe2b3eeb65

STIX ID: report--29fc72d2-d13a-52a0-8f5f-97fe2b3eeb65

Feed Name: SentinelOne Blog

Threat Score
85/100

Date Published: 2025-11-26

Date Updated: 2026-04-30

Author: SentinelOne

...
...

**Shai-Hulud Worm 2.0 — SentinelOne Wayfinder Flash Report (25 Nov 2025):** This report describes an active NPM supply-chain campaign that executes during the preinstall phase to deploy an obfuscated JavaScript payload (bun_environment.js), harvest AWS/GCP/Azure and development secrets (via Trufflehog), and persist by auto-registering self-hosted GitHub Actions runners and writing malicious workflow/discussion entries; it includes IOCs, detection rules, hunting queries, and immediate remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.