Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)
Flags Linux cases where node or bun processes launch trufflehog or gitleaks to search for secrets.
- Product
- linux
- Category
- process_creation
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2025-11-25
- Updated
- 2026-07-31
ATT&CK techniques
Execution → CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule matches process creation on Linux where a script interpreter (parent executable ending in /node or /bun) spawns a process image ending in /trufflehog or /gitleaks, or where the spawned command line contains those tool names. Secret-recovery tooling is often used by attackers to enumerate exposed credentials and tokens within repositories and environments, so interpreter-driven execution can indicate automated reconnaissance. It relies on process creation telemetry that includes parent process image and child process image/command line for accurate string and path matching.
Reporting behind it
- github.comhttps://github.com/asyncapi/cli/blob/2efa4dff59bc3d3cecdf897ccf178f99b115d63d/bun_environment.js
- stepsecurity.iohttps://www.stepsecurity.io/blog/sha1-hulud-the-second-coming-zapier-ens-domains-and-other-prominent-npm-packages-compromised
- endorlabs.comhttps://www.endorlabs.com/learn/shai-hulud-2-malware-campaign-targets-github-and-cloud-credentials-using-bun-runtime
- semgrep.devhttps://semgrep.dev/blog/2025/digging-for-secrets-sha1-hulud-the-second-coming-of-the-npm-worm/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_susp_script_interpretor_spawn_credential_scanner.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)
id: ae987e06-77df-4286-988f-b62e738a7295
related:
- id: 0f60b28c-64dd-4e2c-9a63-5334d3e3a6e6
type: similar
- id: f0025a69-e1b7-4dda-a53c-db21fa2d4071
type: derived
status: experimental
description: This rule matches process creation on Linux where a script interpreter (parent executable ending in /node or /bun) spawns a process image ending in /trufflehog or /gitleaks, or where the spawned command line contains those tool names. Secret-recovery tooling is often used by attackers to enumerate exposed credentials and tokens within repositories and environments, so interpreter-driven execution can indicate automated reconnaissance. It relies on process creation telemetry that includes parent process image and child process image/command line for accurate string and path matching.
references:
- https://github.com/asyncapi/cli/blob/2efa4dff59bc3d3cecdf897ccf178f99b115d63d/bun_environment.js
- https://www.stepsecurity.io/blog/sha1-hulud-the-second-coming-zapier-ens-domains-and-other-prominent-npm-packages-compromised
- https://www.endorlabs.com/learn/shai-hulud-2-malware-campaign-targets-github-and-cloud-credentials-using-bun-runtime
- https://semgrep.dev/blog/2025/digging-for-secrets-sha1-hulud-the-second-coming-of-the-npm-worm/
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_susp_script_interpretor_spawn_credential_scanner.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-11-25
tags:
- attack.credential-access
- attack.t1552
- attack.execution
- attack.collection
- attack.t1005
- attack.t1059.004
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- /node
- /bun
selection_child:
- Image|endswith:
- /trufflehog
- /gitleaks
- CommandLine|contains:
- trufflehog
- gitleaks
condition: all of selection_*
falsepositives:
- Legitimate pre-commit hooks or CI/CD pipeline jobs that use a script to run a credential scanner as part of a security check.
level: high
license: DRL-1.1