ATT&CKReferencesSocket Shai-Hulud November 2025

Socket Shai-Hulud November 2025

Socket Research Team. (2025, November 24). Shai Hulud Strikes Again (v2). Retrieved April 9, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareShai-Hulud

Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes.

T1036.005
Match Legitimate Resource Name or Location
MalwareShai-Hulud

Shai-Hulud has masqueraded as a legitimate Bun installer.

T1036.009
Break Process Trees
MalwareShai-Hulud

Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally.

T1059.004
Unix Shell
MalwareShai-Hulud

Shai-Hulud has utilized Linux shell commands to modify configuration files.

T1059.007
JavaScript
MalwareShai-Hulud

Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js.

T1082
System Information Discovery
MalwareShai-Hulud

Shai-Hulud has gathered victim system information.

T1105
Ingress Tool Transfer
MalwareShai-Hulud

Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareShai-Hulud

Shai-Hulud has published itself on compromised code repository maintainers within infected packages in attempts to propagate to other victims. Shai-Hulud has also modified versions of code packages.

T1485
Data Destruction
MalwareShai-Hulud

Shai-Hulud has destroyed the victim’s home directory by overwriting and deleting every writable file within the user's home folder. Shai-Hulud has also utilized the `shred` command on Linux devices.

T1528
Steal Application Access Token
MalwareShai-Hulud

Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories.

T1543.002
Systemd Service
MalwareShai-Hulud

Shai-Hulud has stopped `systemd-resolved` in order to manipulate DNS and firewalls.

T1546.016
Installer Packages
MalwareShai-Hulud

Shai-Hulud has inserted a new lifecycle hook to include `postinstall`. Shai-Hulud has also leveraged the NPM lifecycle hook `preinstall`.

T1548.003
Sudo and Sudo Caching
MalwareShai-Hulud

Shai-Hulud has attempted to gain root access by leveraging `sudo` and `/etc/sudoers.d`.

T1550.001
Application Access Token
MalwareShai-Hulud

Shai-Hulud has leveraged captured valid NPM tokens to enumerate and update packages on compromised accounts. Shai-Hulud has also utilized stolen GitHub access tokens to access compromised accounts.

T1552.001
Credentials In Files
MalwareShai-Hulud

Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files.

T1553
Subvert Trust Controls
MalwareShai-Hulud

Shai-Hulud has suppressed victim NPM warnings using `process[“exit’](0x0);` which results in having all errors exit with code 0.

T1555.006
Cloud Secrets Management Stores
MalwareShai-Hulud

Shai-Hulud has gathered secrets from AWS Secrets and GCP Secret Manager. Shai-Hulud has also gathered data from Azure Key Vault.

T1564.011
Ignore Process Interrupts
MalwareShai-Hulud

Shai-Hulud has suppressed NPM warnings by silently exiting through the use of the NPM success code that has a setting that all errors exit with `code 0`.

T1567.001
Exfiltration to Code Repository
MalwareShai-Hulud

Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories.

T1677
Poisoned Pipeline Execution
MalwareShai-Hulud

Shai-Hulud has also leveraged GitHub actions from stolen accounts in order to create a malicious Github workflow within `.github/workflows/discussion.yaml`.

T1685
Disable or Modify Tools
MalwareShai-Hulud

Shai-Hulud has replaced DNS configuration from `/tmp/resolved.conf` in order to gain control of network-level control within CI environments and has flushed iptables rules using `sudo iptables -F OUTPUT` and `sudo iptables -F DOCKER-USER`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.