ATT&CKReferencesPalo Alto Unit 42 Shai-Hulud November 2025

Palo Alto Unit 42 Shai-Hulud November 2025

Justin Moore. (2025, November 25). "Shai-Hulud" Worm Compromises npm Ecosystem in Supply Chain Attack (Updated November 26). Retrieved April 9, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareShai-Hulud

Shai-Hulud has masqueraded as a legitimate Bun installer.

T1036.009
Break Process Trees
MalwareShai-Hulud

Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally.

T1041
Exfiltration Over C2 Channel
MalwareShai-Hulud

Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL.

T1059.007
JavaScript
MalwareShai-Hulud

Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js.

T1078.004
Cloud Accounts
MalwareShai-Hulud

Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories.

T1485
Data Destruction
MalwareShai-Hulud

Shai-Hulud has destroyed the victim’s home directory by overwriting and deleting every writable file within the user's home folder. Shai-Hulud has also utilized the `shred` command on Linux devices.

T1528
Steal Application Access Token
MalwareShai-Hulud

Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories.

T1546.016
Installer Packages
MalwareShai-Hulud

Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`.

T1552.001
Credentials In Files
MalwareShai-Hulud

Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files.

T1567.001
Exfiltration to Code Repository
MalwareShai-Hulud

Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories.

T1677
Poisoned Pipeline Execution
MalwareShai-Hulud

Shai-Hulud has also leveraged GitHub actions from stolen accounts in order to create a malicious Github workflow within `.github/workflows/discussion.yaml`.

T1678
Delay Execution
MalwareShai-Hulud

Shai-Hulud has delayed execution of its larger payloads by forking itself into background process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.