Justin Moore. (2025, November 25). "Shai-Hulud" Worm Compromises npm Ecosystem in Supply Chain Attack (Updated November 26). Retrieved April 9, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareShai-Hulud | Shai-Hulud has masqueraded as a legitimate Bun installer. |
| T1036.009 Break Process Trees |
MalwareShai-Hulud | Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally. |
| T1041 Exfiltration Over C2 Channel |
MalwareShai-Hulud | Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL. |
| T1059.007 JavaScript |
MalwareShai-Hulud | Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js. |
| T1078.004 Cloud Accounts |
MalwareShai-Hulud | Shai-Hulud has leveraged compromised accounts to log into cloud services to access cloud hosted repositories. |
| T1485 Data Destruction |
MalwareShai-Hulud | Shai-Hulud has destroyed the victim’s home directory by overwriting and deleting every writable file within the user's home folder. Shai-Hulud has also utilized the `shred` command on Linux devices. |
| T1528 Steal Application Access Token |
MalwareShai-Hulud | Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories. |
| T1546.016 Installer Packages |
MalwareShai-Hulud | Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`. |
| T1552.001 Credentials In Files |
MalwareShai-Hulud | Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files. |
| T1567.001 Exfiltration to Code Repository |
MalwareShai-Hulud | Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories. |
| T1677 Poisoned Pipeline Execution |
MalwareShai-Hulud | Shai-Hulud has also leveraged GitHub actions from stolen accounts in order to create a malicious Github workflow within `.github/workflows/discussion.yaml`. |
| T1678 Delay Execution |
MalwareShai-Hulud | Shai-Hulud has delayed execution of its larger payloads by forking itself into background process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.