Suspicious Remote Script Piped Directly to Interpreter in CI Pipeline

PremiumReviewedSigma · Medium · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects curl fetching a remote payload and piping it straight into bash or node as observed in CI CD pipeline abuse research by Elastic. Executing untrusted remote code without staging is a common supply chain and pipeline compromise technique that bypasses review controls.

Related detections9 linkedT1059.004 — drag to rearrange
Malicious Node Runtime Spawning Shell to Download Python Payload via Axios Compromise
Linux process chain for Axios NPM compromise: curl download with nohup and python3
macOS: Detect Axios malicious npm execution chain using osascript, curl download, and cleanup
Malicious Remote Script Piped to Shell via Curl (via process_creation)
Suspicious Secret Scanning with trufflehog Verified Results
Possible GTFOBins Shell Breakout via Unix Utilities
Malicious Foomatic-Rip Filter Spawning Shell via CUPS Exploitation
Suspicious Downloaded Shell Stager Made Executable Via Chmod 777
Malicious Shai-Hulud Workflow File Creation
Suspicious Remote Script Piped Directly to Interpreter in CI Pipeline
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.