Linux File Events: Malicious GitHub Workflow File Creation (shai-hulud-workflow*.yml/yaml)

Alerts on new .github/workflows YAML files named for Shai-Hulud, indicating potential malicious GitHub Actions persistence.

FreeReviewedSigma · High · v5
Product
linux
Category
file_event
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-09-24
Updated
2026-07-31

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags the creation of specific GitHub Actions workflow files under .github/workflows with names matching shai-hulud-workflow*.yml/yaml. Creating workflow definitions can enable persistence and automation that may access or exfiltrate sensitive repository information when actions run. It relies on Linux file creation telemetry for paths ending in the listed workflow filenames.

Related detections9 linkedT1552.001 — drag to rearrange
Suspicious Recursive Credential and Wallet Search Written to Temp Inventory File
Windows Process Creation: Automated Document and Directory Discovery via dir and findstr
Suspicious UAT-10608 Hidden Credential Harvesting Script Execution via nohup
Suspicious Access to Cloud and Database Credential Files via Process
Suspicious Credential Exfiltration to webhook.site (via dns_query)
Suspicious LameHug Staging Directory and Info File Creation on Windows
Suspicious Shai-Hulud Worm Stager Execution from Temp (via process_creation)
Suspicious prt-scan Campaign Credential Harvesting via proc environ Scan (via process_creation)
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Linux File Events: Malicious GitHub Workflow File Creation (shai-hulud-workflow*.yml/yaml)
Pivot detection · T1552.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.