Suspicious Shai-Hulud Worm Stager Execution from Temp (via process_creation)

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-08-15
Updated
2026-08-28

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects execution of the processor.sh or migrate-repos.sh shell scripts from the tmp directory used by the Shai-Hulud npm supply-chain worm. These stagers harvest cloud and repository credentials then drive self-propagation by republishing infected packages. Running these named scripts out of tmp is a direct indicator of the worm on a developer or build host.

Related detections9 linkedT1552.001 — drag to rearrange
Suspicious Double Base64 Decoded Payload Piped to Shell in CI (reviewdog Supply Chain)
Possible CI Runner Memory Scraping via Python Process Memory Read (tj-actions Supply Chain)
Malicious TeamPCP durabletask Payload python3 managed.pyz from tmp (via process_creation)
Suspicious Access to Cloud and Database Credential Files via Process
Suspicious Credential Exfiltration to webhook.site (via dns_query)
Malicious PowerShell Download from bullethost.cloud Staging Server
Suspicious NPM Install Hook Executing Setup Script via Node
Suspicious prt-scan Campaign Credential Harvesting via proc environ Scan (via process_creation)
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious Shai-Hulud Worm Stager Execution from Temp (via process_creation)
Pivot detection · T1552.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.