GajIPS - IPS Signature Update — GS TROJAN: Shai-Hulud npm supply-chain worm data exfiltration
Severity: HIGH · Priority: P2 — probable developer-system compromise, investigate on hit
This rule raises an alert when a device on your network sends data to the specific web address used by the Shai-Hulud worm to steal secrets. Shai-Hulud is a self-spreading worm that infected hundreds of packages in the npm software ecosystem (the library repository used by JavaScript/Node.js developers) beginning September 2025. When a developer installs a compromised package, the malware harvests credentials — npm and GitHub tokens, and cloud secrets from AWS and Google — and sends them to a hardcoded collection point. It then uses the stolen GitHub access to spread itself further and to make the victim's private code repositories public. This rule watches for the outbound connection to that exact collection address.
A hit strongly suggests a developer machine on your network is infected and is leaking credentials. The address this rule matches has no legitimate use — it is the worm's specific, hardcoded drop point — so a match is a high-confidence indicator, not routine noise. Treat it as a probable compromise of the originating machine and the developer's accounts: identify the device and user, and treat all their credentials as exposed — rotate npm and GitHub tokens, and any cloud (AWS/Google) secrets that machine could reach, from a known-clean system. Then hunt for the worm's other fingerprints: a malicious workflow file named shai-hulud-workflow.yml in code repositories, unexpected public repositories or a repository named "Shai-Hulud" under affected accounts, and the compromised package versions in project dependencies.