ATT&CKReferencesSocket Shai-Hulud Trufflehog September 2025

Socket Shai-Hulud Trufflehog September 2025

Socket Research Team. (2025, September 15). Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages. Retrieved April 9, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareShai-Hulud

Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account. Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes.

T1059.007
JavaScript
MalwareShai-Hulud

Shai-Hulud has used JavaScript to create JSON file output and run scripts using node.js.

T1105
Ingress Tool Transfer
MalwareShai-Hulud

Shai-Hulud has downloaded packages from code repositories. Shai-Hulud has also downloaded and executed the secrets-discovery tool TruffleHog to gather sensitive data.

T1550.001
Application Access Token
MalwareShai-Hulud

Shai-Hulud has leveraged captured valid NPM tokens to enumerate and update packages on compromised accounts. Shai-Hulud has also utilized stolen GitHub access tokens to access compromised accounts.

T1552.001
Credentials In Files
MalwareShai-Hulud

Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files.

T1567.001
Exfiltration to Code Repository
MalwareShai-Hulud

Shai-Hulud has created a repository named `Shai-Hulud` under the compromised account that commits a JSON dump that contains system information, environment variables and collected secrets. Shai-Hulud has also posted stolen credentials to public GitHub repositories.

T1608.001
Upload Malware
MalwareShai-Hulud

Shai-Hulud has published malicious gzip-compressed tarball (.tgz) following modification of packages within compromised accounts. Shai-Hulud has also modified packages within compromised accounts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.