logo

From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach

ID: 09dfad87-c7ef-5615-a33d-569a1e13fa3f

STIX ID: report--09dfad87-c7ef-5615-a33d-569a1e13fa3f

Feed Name: Fortinet Blog

Threat Score
80/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

...
...

**Executive summary:** The Fortinet report details the "Shai Hulud" supply‑chain worm (TeamPCP) that injected malicious npm/PyPI packages to run inside CI/CD runners, harvest build and cloud credentials, and leverage those credentials to access AWS (Jenkins instance role abuse), create an admin IAM user (cloudops-monitor), escalate privileges, manipulate RDS/Redshift security groups, enumerate Secrets Manager, execute Redshift Data API queries for large-scale collection, and stage exfiltration to S3 and SES; FortiCNAPP detections, representative IOCs (185.204.1.225, 89.22.231.63, cloudops-monitor, exfil* session names, exfil-s3-* policies), and defensive recommendations are included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.