Linux: Bun runtime execution of bun_environment.js from node parent process

Flags /node-launched /bun executions running bun_environment.js with an external runner release download URL.

FreeUnreviewedSigmahighv1
title: "Linux: Bun runtime execution of bun_environment.js from node parent process"
id: 0e1dee9a-e81d-4450-a2f3-d3aa12534313
related:
  - id: 5299fadf-f228-4526-8274-251db1960be9
    type: similar
  - id: eb827bbd-670a-4d58-8446-c464d8ac2323
    type: derived
status: experimental
description: This rule identifies process creations where a parent process whose path ends with /node spawns a /bun binary executing a command line containing bun_environment.js. It also requires the command line to include an external download URL, indicating the environment preparation and payload retrieval typical of staged script execution. The detection relies on Linux process creation telemetry with process image paths and full command-line content.
references:
  - https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
  - https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack
  - https://github.com/asyncapi/cli/blob/2efa4dff59bc3d3cecdf897ccf178f99b115d63d/setup_bun.js
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Malware/Shai-Hulud/proc_creation_lnx_mal_shai_hulud_malicious_node_bun_execution.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-11-25
tags:
  - attack.t1195.002
  - attack.t1203
  - attack.execution
  - attack.initial-access
  - detection.emerging-threats
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith: /node
  selection_child_bun:
    Image|endswith: /bun
    CommandLine|contains:
      - bun_environment.js
      - https://github.com/actions/runner/releases/download/v2.330.0
  selection_child_setup_curl:
    CommandLine|contains|all:
      - "curl "
      - -fsSL
      - https://bun.sh/install
      - bash
  selection_child_path_reload:
    CommandLine|contains|all:
      - 'bash -c "source '
      - "&& echo"
  condition: selection_parent and 1 of selection_child_*
falsepositives:
  - Legitimate but uncommon use of files named `bun_environment.js` could trigger this rule.
level: high
license: DRL-1.1

What it detects

This rule identifies process creations where a parent process whose path ends with /node spawns a /bun binary executing a command line containing bun_environment.js. It also requires the command line to include an external download URL, indicating the environment preparation and payload retrieval typical of staged script execution. The detection relies on Linux process creation telemetry with process image paths and full command-line content.

Known false positives

  • Legitimate but uncommon use of files named `bun_environment.js` could trigger this rule.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.