Malicious Shai-Hulud Workflow File Creation

PremiumReviewedSigma · High · v1
Category
file_event
Author
HuntRule
Published
2026-09-16
Updated
2026-09-16

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation of a shai-hulud-workflow.yml file, the malicious GitHub Actions workflow dropped by the Shai-Hulud npm supply-chain worm to establish persistence and propagate through developer repositories. The distinctive filename is a reliable indicator of compromise.

Related detections9 linkedT1195.002 — drag to rearrange
Suspicious Salesforce OAuth Refresh Token Use by Klue Battlecards App
Malicious axios NPM Supply Chain Persistence via MicrosoftUpdate Run Key
Malicious Registry Run Key Persistence Masquerading as MicrosoftUpdate
Suspicious Node.js Spawning Script Interpreter for Dropped Payload
Malicious Node.js Execution of Hidden .claude Setup Script
Malicious axios NPM Supply Chain C2 Domain Resolution
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Suspicious TrueConf Update Chain Spawning Temporary Executable in Operation TrueChaos
Malicious Shai-Hulud Workflow File Creation
Pivot detection · T1195.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.