{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "The Shai-Hulud framework contains a credible threat of data destruction during incident response; detecting the deadman switch is required to prevent large-scale data loss when credentials are rotated."
      },
      "name": "Shai-Hulud: Exfiltration and Deadman Switch",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1071.001",
        "attack.t1090.003",
        "attack.t1567.001",
        "attack.t1485"
      ],
      "series": {
        "slug": "shai-hulud-open-source-framework-static-analysis",
        "index": 3,
        "title": "Shai-Hulud open source framework static analysis",
        "total": 3
      },
      "related": [
        {
          "hunt": "shai-hulud-persistence-and-harvesting",
          "reason": "Initial access through supply chain poisoning and local credential harvesting are handled in separate hunts.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "shai-hulud-secret-harvesting-discovery",
          "relation": "follows"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single detection rule for the C2 domain fails if infrastructure rotates; this hunt correlates the network signal with the prevalence of API polling and the behavioural footprint of the persistence daemon and its destructive payload, providing context an analyst must weigh before acting.",
      "coverage": [
        {
          "stage": "c2-encrypted-communications",
          "steps": [
            "lead-dns-c2",
            "http-github-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "exfiltration-github-dead-drops",
          "steps": [
            "http-github-activity"
          ],
          "status": "covered"
        },
        {
          "stage": "impact-destructive-wipe",
          "steps": [
            "process-monitor-and-wipe"
          ],
          "status": "covered"
        },
        {
          "stage": "initial-access-supply-chain-poisoning",
          "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "execution-loader-bootstrap",
          "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "persistence-daemon-and-deadman-monitor",
          "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "credential-access-memory-and-file-harvesting",
          "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "discovery-cloud-infrastructure-enumeration",
          "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Supply Chain Poisoning & Repository Hijacking",
            "slug": "initial-access-supply-chain-poisoning",
            "tactic": "initial-access",
            "techniques": [
              "T1195",
              "T1133"
            ],
            "observables": [
              "hijacked Trivy and Checkmarx KICS tags",
              "poisoned LiteLLM, TanStack, and UiPath npm/PyPI packages",
              ".vscode/tasks.json with runOn: folderOpen",
              ".claude/settings.json SessionStart hook",
              "claude@users.noreply.github.com"
            ]
          },
          {
            "name": "Multi-language Loader Execution",
            "slug": "execution-loader-bootstrap",
            "tactic": "execution",
            "techniques": [
              "T1059.004",
              "T1059.007"
            ],
            "observables": [
              "BASH_LOADER.sh",
              "PYTHON_LOADER.py",
              "config.mjs",
              "setup.mjs",
              "router_init.js",
              "opensearch_init.js",
              "node .claude/setup.mjs",
              "Bun runtime download"
            ]
          },
          {
            "name": "Daemonized Persistence & Token Monitoring",
            "slug": "persistence-daemon-and-deadman-monitor",
            "tactic": "persistence",
            "techniques": [
              "T1543.001",
              "T1543.002"
            ],
            "observables": [
              "/tmp/tmp.ts018051808.lock",
              "~/Library/LaunchAgents/com.user.gh-token-monitor.plist",
              "~/.config/systemd/user/gh-token-monitor.service",
              "loginctl enable-linger",
              "__DAEMONIZED=1"
            ]
          },
          {
            "name": "Memory Secret Extraction & Credential Harvesting",
            "slug": "credential-access-memory-and-file-harvesting",
            "tactic": "credential-access",
            "techniques": [
              "T1003.001",
              "T1552.001",
              "T1555"
            ],
            "observables": [
              "Runner.Worker",
              "/proc/*/mem scanning",
              "gh auth token",
              "~/.aws/credentials",
              "~/.azure/accessTokens.json",
              "~/.config/gcloud/credentials.db",
              "~/.kube/config",
              "/var/run/secrets/kubernetes.io/serviceaccount/token",
              ".npmrc",
              ".pypirc",
              ".claude.json"
            ]
          },
          {
            "name": "Cloud and K8s Secret Discovery",
            "slug": "discovery-cloud-infrastructure-enumeration",
            "tactic": "discovery",
            "techniques": [
              "T1580",
              "T1082"
            ],
            "observables": [
              "AWS Secrets Manager enumeration",
              "SSM Parameter Store enumeration",
              "Kubernetes namespace listing",
              "HashiCorp Vault KV mount enumeration"
            ]
          },
          {
            "name": "Encrypted Domain-based C2",
            "slug": "c2-encrypted-communications",
            "tactic": "command-and-control",
            "techniques": [
              "T1071.001",
              "T1090.003"
            ],
            "observables": [
              "git-tanstack[.]com",
              "thebeautifulmarchoftime GitHub commit search",
              "RSA-4096-OAEP",
              "AES-256-GCM"
            ]
          },
          {
            "name": "GitHub Dead-drop Exfiltration",
            "slug": "exfiltration-github-dead-drops",
            "tactic": "exfiltration",
            "techniques": [
              "T1567.001"
            ],
            "observables": [
              "Shai-Hulud: Here We Go Again repository description",
              "Dune-themed repo names (sardaukar, mentat, stillsuit)",
              "results/ directory JSON commits",
              "IfYouRevokeThisTokenItWillWipeTheComputerOfTheOwner"
            ]
          },
          {
            "name": "Conditional Data Destruction",
            "slug": "impact-destructive-wipe",
            "tactic": "impact",
            "techniques": [
              "T1485"
            ],
            "observables": [
              "rm -rf ~/",
              "HTTP 40x response from https://api.github.com/user"
            ]
          }
        ],
        "summary": "The Shai-Hulud framework by TeamPCP is a modular TypeScript toolkit that targets CI/CD pipelines and developer workstations through supply chain poisoning of npm/PyPI packages and IDE configurations. It extracts credentials from process memory, cloud environments, and local files before exfiltrating encrypted data to C2 domains or GitHub dead-drop repositories, featuring a 'deadman switch' that wipes the user directory if stolen tokens are revoked."
      },
      "severity": "high",
      "rationale": "Start with developer workstations and CI/CD runners where GitHub and cloud credentials are most prevalent. Focus on hosts with Linux or macOS profiles.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.",
      "parameters": {
        "c2_domains": {
          "from": {
            "ref": "Shai-Hulud static analysis",
            "kind": "article",
            "observed": "2026-05-12"
          },
          "type": "list[domain]",
          "default": [
            "git-tanstack.com"
          ],
          "description": "Primary C2 domains identified in the Shai-Hulud framework."
        },
        "scope_hosts": {
          "from": {
            "ref": "analyst-entry",
            "kind": "manual",
            "observed": "2026-05-12"
          },
          "type": "list[host]",
          "default": [],
          "description": "A list of hostnames to narrow the search; leave empty to hunt across the entire estate."
        },
        "lookback_days": {
          "from": {
            "ref": "retention-policy",
            "kind": "manual",
            "observed": "2026-05-12"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "fallback_search_string": {
          "from": {
            "ref": "Shai-Hulud static analysis",
            "kind": "article",
            "observed": "2026-05-12"
          },
          "type": "string",
          "default": "thebeautifulmarchoftime",
          "description": "The signed string used to locate rotated C2 domains on GitHub."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/",
          "name": "Shai-Hulud open source framework static analysis"
        }
      ],
      "blind_spots": [
        {
          "id": "no-process-visibility",
          "risk": "A host without process logging could have its token revoked by an administrator, triggering the destruction before the hunt identifies the threat.",
          "stage": "impact-destructive-wipe",
          "question": "whether the deadman switch is currently monitoring a token",
          "requires": "hb_process_activity with command-line arguments"
        },
        {
          "id": "github-search-visibility",
          "risk": "If the primary C2 domain is blocked, the attacker can rotate infrastructure via signed commits; without visibility into the GitHub search query, we cannot see the transition.",
          "stage": "c2-encrypted-communications",
          "question": "if the host searched GitHub for a rotated C2 domain",
          "requires": "hb_http_activity with full URL query parameters"
        }
      ]
    },
    "name": "Shai-Hulud: Exfiltration and Deadman Switch",
    "description": "The Shai-Hulud framework employs a sophisticated exfiltration pipeline that prioritizes domain-based C2 before falling back to GitHub repository dead-drops. Crucially, the framework installs a monitoring daemon that polls the GitHub API to detect token revocation. If the token is invalidated by the defender, the daemon executes a destructive command to wipe the user's home directory. This hunt identifies the network-facing exfiltration activity and the behavioural footprint of the deadman switch to ensure safe remediation."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "shai-hulud-open-source-framework-static-analysis",
          "index": 3,
          "title": "Shai-Hulud open source framework static analysis",
          "total": 3
        },
        "coverage": [
          {
            "stage": "c2-encrypted-communications",
            "steps": [
              "lead-dns-c2",
              "http-github-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "exfiltration-github-dead-drops",
            "steps": [
              "http-github-activity"
            ],
            "status": "covered"
          },
          {
            "stage": "impact-destructive-wipe",
            "steps": [
              "process-monitor-and-wipe"
            ],
            "status": "covered"
          },
          {
            "stage": "initial-access-supply-chain-poisoning",
            "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "execution-loader-bootstrap",
            "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "persistence-daemon-and-deadman-monitor",
            "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "credential-access-memory-and-file-harvesting",
            "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "discovery-cloud-infrastructure-enumeration",
            "reason": "Belongs to another part of the 'Shai-Hulud open source framework static analysis' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An attacker is using the Shai-Hulud framework to exfiltrate stolen credentials through GitHub dead-drops and has installed a destructive deadman switch that triggers a home-directory wipe if tokens are revoked.",
        "blind_spots": [
          {
            "id": "no-process-visibility",
            "risk": "A host without process logging could have its token revoked by an administrator, triggering the destruction before the hunt identifies the threat.",
            "stage": "impact-destructive-wipe",
            "question": "whether the deadman switch is currently monitoring a token",
            "requires": "hb_process_activity with command-line arguments"
          },
          {
            "id": "github-search-visibility",
            "risk": "If the primary C2 domain is blocked, the attacker can rotate infrastructure via signed commits; without visibility into the GitHub search query, we cannot see the transition.",
            "stage": "c2-encrypted-communications",
            "question": "if the host searched GitHub for a rotated C2 domain",
            "requires": "hb_http_activity with full URL query parameters"
          }
        ],
        "scoping_notes": "Start with developer workstations and CI/CD runners where GitHub and cloud credentials are most prevalent. Focus on hosts with Linux or macOS profiles.",
        "beyond_detection": "A single detection rule for the C2 domain fails if infrastructure rotates; this hunt correlates the network signal with the prevalence of API polling and the behavioural footprint of the persistence daemon and its destructive payload, providing context an analyst must weigh before acting."
      }
    },
    {
      "id": "lead-dns-c2",
      "type": "query",
      "label": "Primary C2 domain lookups",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_dns_activity",
        "description": "Identify hosts resolving the framework's primary C2 domain to scope the investigation.",
        "expected_signal": "A list of hosts that contacted the default framework infrastructure. Silence proves only that the default domain was not used."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Primary C2 domain lookups",
        "reads": [
          "device_hostname",
          "query_hostname",
          "time"
        ],
        "source": "hb_dns_activity",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts that contacted the default framework infrastructure. Silence proves only that the default domain was not used.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "process-monitor-and-wipe",
      "type": "query",
      "label": "Monitor daemon and destructive activity",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, user_name, process_name, process_cmd_line, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%gh-token-monitor%' OR LOWER(process_cmd_line) LIKE '%rm -rf%' OR LOWER(process_cmd_line) LIKE '%tmp.ts018051808.lock%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Detect the execution of the Shai-Hulud monitoring daemon or the destructive wipe command itself.",
        "expected_signal": "The presence of the gh-token-monitor process or a broad directory deletion command. This is the definitive indicator of a framework infection."
      },
      "parents": [
        {
          "id": "lead-dns-c2"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Monitor daemon and destructive activity",
        "reads": [
          "device_hostname",
          "user_name",
          "process_name",
          "process_cmd_line",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, user_name, process_name, process_cmd_line, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%gh-token-monitor%' OR LOWER(process_cmd_line) LIKE '%rm -rf%' OR LOWER(process_cmd_line) LIKE '%tmp.ts018051808.lock%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "The presence of the gh-token-monitor process or a broad directory deletion command. This is the definitive indicator of a framework infection.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "http-github-activity",
      "type": "query",
      "label": "GitHub API activity and rotation",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, COUNT(*) AS request_count, MIN(time) AS first_seen FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND ( (LOWER(url_hostname) = 'api.github.com' AND LOWER(url_path) = '/user') OR url_full LIKE '%' || '{{fallback_search_string}}' || '%' ) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_hostname, url_path",
        "surface": "hb_http_activity",
        "description": "Identify high-frequency GitHub API polling or searches for rotated C2 infrastructure.",
        "expected_signal": "A high count of requests to the GitHub user endpoint per host, indicating the deadman switch is polling for revocation. Silence on the rotation string is expected unless infrastructure has rotated."
      },
      "parents": [
        {
          "id": "lead-dns-c2"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "GitHub API activity and rotation",
        "reads": [
          "device_hostname",
          "url_hostname",
          "url_path",
          "url_full",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, COUNT(*) AS request_count, MIN(time) AS first_seen FROM hb_http_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND ( (LOWER(url_hostname) = 'api.github.com' AND LOWER(url_path) = '/user') OR url_full LIKE '%' || '{{fallback_search_string}}' || '%' ) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_hostname, url_path",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A high count of requests to the GitHub user endpoint per host, indicating the deadman switch is polling for revocation. Silence on the rotation string is expected unless infrastructure has rotated.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "url_hostname",
            "url_path"
          ],
          "rare_below": 3
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "triage-agent",
      "type": "analytic",
      "label": "Triage exfiltration and deadman switch",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "web"
        ],
        "context": [
          "lead-dns-c2",
          "process-monitor-and-wipe",
          "http-github-activity"
        ],
        "objective": "Determine if the evidence indicates a Shai-Hulud framework infection and evaluate whether a destructive deadman switch is active on any host.",
        "description": "Correlate the DNS, process, and HTTP evidence to confirm framework presence and assess the risk of data destruction.",
        "max_iterations": 5,
        "expected_signal": "A verdict that links the exfiltration attempts to the monitoring daemon and identifies hosts at risk of a home-directory wipe.",
        "success_criteria": "A per-host verdict of malicious | suspicious | benign citing specific rows from the process and HTTP surfaces."
      },
      "parents": [
        {
          "id": "process-monitor-and-wipe",
          "kind": "merge"
        },
        {
          "id": "http-github-activity",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-agent verdict is malicious for at least one host and identifies the token-monitoring daemon or destructive file deletion commands",
        "condition": "the triage-agent verdict is malicious for at least one host and identifies the token-monitoring daemon or destructive file deletion commands",
        "blind_spot": "no-process-visibility",
        "confidence": "high",
        "description": "Isolate hosts with confirmed infections to prevent data destruction during token revocation.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-agent"
        }
      ]
    },
    {
      "id": "isolate-host",
      "type": "action",
      "label": "Isolate host",
      "config": {
        "target": "endpoint",
        "description": "Halt exfiltration and prevent the deadman switch from executing its payload.",
        "instructions": "Isolate the host immediately. Terminate the gh-token-monitor process and any instances of Bun or Node running malicious scripts before revoking any identified GitHub tokens.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "token-investigation",
      "type": "task",
      "label": "Review leaked tokens",
      "config": {
        "assignee": "analyst",
        "description": "Identify the scope of the credential compromise to prepare for remediation.",
        "instructions": "Audit GitHub, AWS, and Kubernetes secrets for any tokens originating from the identified hosts. Check user shell histories and configuration files for exposed material."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-host"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Document findings and propose permanent detections.",
        "instructions": "Summarize the findings. If the gh-token-monitor or the git-tanstack.com domain were confirmed, recommend promoting the associated queries to standing detection rules."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "token-investigation"
        }
      ]
    }
  ]
}