Shai-Hulud has utilized double-base64 encoding to store stolen secrets within the Github Action Logs within the victim account.891011 Shai-Hulud has also leveraged three layers of base64 encoding of exfiltrated data for anti-forensic purposes.12
tool
Shai-Hulud S9008
- Type
- malware
- Platforms
- Linux, SaaS, Windows
- Created
- 9 April 2026
- Last modified
- 24 April 2026
Shai-Hulud is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM packages. It exploits CI/CD pipeline dependencies to propagate to victims and poisons the supply chain by publishing malicious packages. Once inside a victim environment, Shai-Hulud steals credentials and access tokens from compromised repository accounts and exfiltrates them to attacker-controlled servers via encoded GitHub Actions workflows.[1][2][3][4][5][6][7]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S9008
Shai-Hulud has masqueraded as a legitimate Bun installer.1314
Shai-Hulud has augmented its installation process by having its original install process exit cleanly to provide the user with the illusion that the service is installed normally.1516
Shai-Hulud has used POST to exfiltrate secrets from the victim environment to an attacker-controlled URL.171819
Shai-Hulud has utilized PowerShell Invoke-WebRequest to download and install the malicious payload.20
Shai-Hulud has utilized Linux shell commands to modify configuration files.21
Standing S9008
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
94th percentile · 94% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
100th percentile · None of the 825 ATT&CK software entries has more tactics spanned — the highest in the population.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
18th percentile · 82% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S9008
1222 distinct rules cover the 33 techniques recorded for this tool. The 1360 technique-to-rule mappings resolve to 1222 distinct rules, because one rule can cover several techniques. 788 Sigma · 434 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org