Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)

Flags Linux cases where node or bun processes launch trufflehog or gitleaks to search for secrets.

FreeReviewedSigma · High · v2
Product
linux
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-11-25
Updated
2026-07-31
title: Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)
id: ae987e06-77df-4286-988f-b62e738a7295
related:
  - id: 0f60b28c-64dd-4e2c-9a63-5334d3e3a6e6
    type: similar
  - id: f0025a69-e1b7-4dda-a53c-db21fa2d4071
    type: derived
status: experimental
description: This rule matches process creation on Linux where a script interpreter (parent executable ending in /node or /bun) spawns a process image ending in /trufflehog or /gitleaks, or where the spawned command line contains those tool names. Secret-recovery tooling is often used by attackers to enumerate exposed credentials and tokens within repositories and environments, so interpreter-driven execution can indicate automated reconnaissance. It relies on process creation telemetry that includes parent process image and child process image/command line for accurate string and path matching.
references:
  - https://github.com/asyncapi/cli/blob/2efa4dff59bc3d3cecdf897ccf178f99b115d63d/bun_environment.js
  - https://www.stepsecurity.io/blog/sha1-hulud-the-second-coming-zapier-ens-domains-and-other-prominent-npm-packages-compromised
  - https://www.endorlabs.com/learn/shai-hulud-2-malware-campaign-targets-github-and-cloud-credentials-using-bun-runtime
  - https://semgrep.dev/blog/2025/digging-for-secrets-sha1-hulud-the-second-coming-of-the-npm-worm/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_susp_script_interpretor_spawn_credential_scanner.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-11-25
tags:
  - attack.credential-access
  - attack.t1552
  - attack.execution
  - attack.collection
  - attack.t1005
  - attack.t1059.004
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - /node
      - /bun
  selection_child:
    - Image|endswith:
        - /trufflehog
        - /gitleaks
    - CommandLine|contains:
        - trufflehog
        - gitleaks
  condition: all of selection_*
falsepositives:
  - Legitimate pre-commit hooks or CI/CD pipeline jobs that use a script to run a credential scanner as part of a security check.
level: high
license: DRL-1.1