Shai-Hulud
A Javascript-based worm propagating through GitHub repositories and exfiltrating tokens and other credentials. Source: MISP
Activity on Jábega · 12 weeks
1 stories · first seen on 22 Sep 2026 · last seen on 22 Sep 2026
News
- Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub DataDark Reading · 22 Sep 2026
MITRE ATT&CK techniques
Reconnaissance
Resource Development
Initial Access
T1078.004Cloud Accounts 35 Sigma rulesT1195.001Compromise Software Dependencies and Development Tools 2 Sigma rules
Execution
T1059.001PowerShell 40 Sigma rulesT1059.004Unix Shell 17 Sigma rulesT1059.007JavaScript 26 Sigma rulesT1677Poisoned Pipeline Execution
Persistence
T1098Account Manipulation 36 Sigma rulesT1543.002Systemd Service 3 Sigma rulesT1546.016Installer Packages
Privilege Escalation
Credential Access
T1528Steal Application Access Token 13 Sigma rulesT1552.001Credentials In Files 20 Sigma rulesT1552.005Cloud Instance Metadata APIT1555.006Cloud Secrets Management Stores
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
T1041Exfiltration Over C2 Channel 4 Sigma rulesT1567.001Exfiltration to Code Repository 1 Sigma rulesT1567.004Exfiltration Over Webhook
Impact
Stealth
T1027Obfuscated Files or Information 61 Sigma rulesT1036.005Match Legitimate Resource Name or Location 20 Sigma rulesT1036.009Break Process TreesT1564.011Ignore Process InterruptsT1678Delay Execution
Defense impairment
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗ malpedia.caad.fkie.fraunhofer.de ↗