Linux: Bun runtime execution of bun_environment.js from node parent process
Flags /node-launched /bun executions running bun_environment.js with an external runner release download URL.
FreeUnreviewedSigmahighv1
linux-bun-runtime-execution-of-bun-environment-js-from-node-parent-process-eb827bbd
title: "Linux: Bun runtime execution of bun_environment.js from node parent process"
id: 0e1dee9a-e81d-4450-a2f3-d3aa12534313
related:
- id: 5299fadf-f228-4526-8274-251db1960be9
type: similar
- id: eb827bbd-670a-4d58-8446-c464d8ac2323
type: derived
status: experimental
description: This rule identifies process creations where a parent process whose path ends with /node spawns a /bun binary executing a command line containing bun_environment.js. It also requires the command line to include an external download URL, indicating the environment preparation and payload retrieval typical of staged script execution. The detection relies on Linux process creation telemetry with process image paths and full command-line content.
references:
- https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
- https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
- https://github.com/asyncapi/cli/blob/2efa4dff59bc3d3cecdf897ccf178f99b115d63d/setup_bun.js
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_lnx_mal_shai_hulud_malicious_node_bun_execution.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-11-25
tags:
- attack.t1195.002
- attack.t1203
- attack.execution
- attack.initial-access
- detection.emerging-threats
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith: /node
selection_child_bun:
Image|endswith: /bun
CommandLine|contains:
- bun_environment.js
- https://github.com/actions/runner/releases/download/v2.330.0
selection_child_setup_curl:
CommandLine|contains|all:
- "curl "
- -fsSL
- https://bun.sh/install
- bash
selection_child_path_reload:
CommandLine|contains|all:
- 'bash -c "source '
- "&& echo"
condition: selection_parent and 1 of selection_child_*
falsepositives:
- Legitimate but uncommon use of files named `bun_environment.js` could trigger this rule.
level: high
license: DRL-1.1
What it detects
This rule identifies process creations where a parent process whose path ends with /node spawns a /bun binary executing a command line containing bun_environment.js. It also requires the command line to include an external download URL, indicating the environment preparation and payload retrieval typical of staged script execution. The detection relies on Linux process creation telemetry with process image paths and full command-line content.
Known false positives
- Legitimate but uncommon use of files named `bun_environment.js` could trigger this rule.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.