Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attack
ID: 0004ab8b-37a4-5747-be08-6f065a204744
STIX ID: report--0004ab8b-37a4-5747-be08-6f065a204744
Feed Name: Microsoft Security
Date Published: 2025-12-09
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
Microsoft describes the Shai‑Hulud 2.0 supply-chain campaign in which threat actors modified hundreds of npm packages to run malicious preinstall scripts that install a Bun runtime, deploy GitHub Actions runners named SHA1HULUD, and use tools such as TruffleHog to harvest and exfiltrate credentials; the report provides technical details, detections, hunting queries, mitigation guidance, and indicators to help defenders identify and contain affected assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
