ATT&CKReferencesNetskope Shai-Hulud November 2025

Netskope Shai-Hulud November 2025

Gianpietro Cutolo. (2025, November 26). Shai-Hulud 2.0: Aggressive, Automated, and Fast Spreading. Retrieved April 9, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1005
Data from Local System
ToolTruffleHog

TruffleHog has gathered data from home directories of the victim environment.

T1027
Obfuscated Files or Information
MalwareShai-Hulud

Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes.

T1059.007
JavaScript
MalwareShai-Hulud

Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js.

T1078.004
Cloud Accounts
MalwareShai-Hulud

Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories.

T1083
File and Directory Discovery
ToolTruffleHog

TruffleHog has can browse and scan individual files and directories.

T1098
Account Manipulation
MalwareShai-Hulud

Shai-Hulud has modified GitHub account settings for private repositories and changed them to public.

T1105
Ingress Tool Transfer
MalwareShai-Hulud

Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data.

T1119
Automated Collection
MalwareShai-Hulud

Shai-Hulud has the ability to automatically collect host data, secrets, system information, and endpoints.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareShai-Hulud

Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages.

T1528
Steal Application Access Token
MalwareShai-Hulud

Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories.

T1546.016
Installer Packages
MalwareShai-Hulud

Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`.

T1552.001
Credentials In Files
MalwareShai-Hulud

Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files.

T1552.001
Credentials In Files
ToolTruffleHog

TruffleHog has obtained credentials stored in config files and credential files in victim environments.

T1555.006
Cloud Secrets Management Stores
MalwareShai-Hulud

Shai-Hulud has gathered secrets from AWS Secrets and GCP Secret Manager. Shai-Hulud has also gathered data from Azure Key Vault.

T1555.006
Cloud Secrets Management Stores
ToolTruffleHog

TruffleHog can obtain secrets from AWS Secrets and GCP Secret Manager. TruffleHog has also gathered passwords, secrets and API keys from source repositories, .env files, and git history.

T1567.001
Exfiltration to Code Repository
MalwareShai-Hulud

Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories.

T1593.003
Code Repositories
MalwareShai-Hulud

Shai-Hulud has the ability to search open sites and code repositories for compromised credentials. Shai-Hulud has discovered packages associated with compromised accounts. Shai-Hulud has also searched code repositories for other compromised repositories that include predefined parameters or markers to include “Second Coming” combined with an 18-character alphanumeric string.

T1608.001
Upload Malware
MalwareShai-Hulud

Shai-Hulud has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts. Shai-Hulud has also modified packages within compromised accounts.

T1677
Poisoned Pipeline Execution
MalwareShai-Hulud

Shai-Hulud has also leveraged GitHub actions from stolen accounts in order to create a malicious Github workflow within `.github/workflows/discussion.yaml`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.