Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S9008
MITRE ATT&CK Malware

Shai-Hulud (S9008)

ShareXLinkedInRedditHN

[Shai-Hulud](https://attack.mitre.org/software/S9008) is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM packages. It exploits CI/CD pipeline dependencies to propagate to victims and poisons the supply chain by publishing malicious packages. Once inside a victim environment, [Shai-Hulud](https://attack.mitre.org/software/S9008) steals credentials and access tokens from compromised repository accounts and exfiltrates them to attacker-controlled servers via encoded GitHub Actions workflows.(Citation: Palo Alto Unit 42 Shai-Hulud November 2025)(Citation: Microsoft Shai-Hulud December 2025)(Citation: Socket Shai-Hulud November 2025)(Citation: Socket Shai-Hulud Trufflehog September 2025)(Citation: Aikido Shai-Hulud September 2025)(Citation: Netskope Shai-Hulud November 2025)(Citation: Wiz Shai-Hulud September 2025)

Platforms: Linux, SaaS, Windows

▪Techniques implemented (33)

T1027Obfuscated Files or InformationT1548.003Sudo and Sudo CachingT1543.002Systemd ServiceT1678Delay ExecutionT1677Poisoned Pipeline ExecutionT1485Data DestructionT1552.001Credentials In FilesT1685Disable or Modify ToolsT1195.001Compromise Software Dependencies and Development ToolsT1105Ingress Tool TransferT1059.004Unix ShellT1078.004Cloud AccountsT1555.006Cloud Secrets Management StoresT1564.011Ignore Process InterruptsT1119Automated CollectionT1071.001Web ProtocolsT1593.003Code RepositoriesT1567.001Exfiltration to Code RepositoryT1036.009Break Process TreesT1528Steal Application Access TokenT1098Account ManipulationT1553Subvert Trust ControlsT1036.005Match Legitimate Resource Name or LocationT1041Exfiltration Over C2 ChannelT1546.016Installer PackagesT1608.001Upload MalwareT1567.004Exfiltration Over WebhookT1213.003Code RepositoriesT1059.001PowerShellT1552.005Cloud Instance Metadata APIT1082System Information DiscoveryT1550.001Application Access TokenT1059.007JavaScript
S9008on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.