Threat hunts for Jenkins
2 hunts covering Jenkins, each with a hypothesis, the queries that test it and what the hunt cannot see.
2 hunts
-
high Part 2 of 2Research by Unit 42
ChainDrop Worm: Developer Tooling Persistence and Supply Chain Propagation
An adversary has compromised developer environments by injecting malicious hooks into IDE configuration files, using automated GitHub workflows to propagate an npm worm and resolve C2 via Ethereum smart contracts.
4 query1 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution -
high Part 1 of 2Research by Unit 42
ChainDrop: NPM Worm Endpoint and CI Runner Activity
An intruder has infected an npm package and triggered a preinstall hook that uses the Bun runtime to harvest credentials from the filesystem and CI runner process memory.
5 query2 analytic1 checkpoint1 action2 taskcommand and control · credential access · execution