Suspicious Shai-Hulud GitHub Workflow File Drop (via file_event)

PremiumReviewedSigma · High · v1
Category
file_event
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule detects creation of a shai-hulud-workflow.yml GitHub Actions workflow file planted by the Shai-Hulud npm worm. The malicious workflow is written into infected repositories to persist and to exfiltrate secrets to attacker infrastructure. The distinctive workflow filename is a reliable artifact of this supply-chain compromise.

Related detections2 linkedT1567.001 — drag to rearrange
GitHub Pages repository site changed to public (repo.pages_public audit event)
Windows Network Connections to *.devtunnels.ms
Suspicious Shai-Hulud GitHub Workflow File Drop (via file_event)
Pivot detection · T1567.001 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.