A comprehensive cybersecurity tool for detecting Shai Hulud campaign indicators across GitHub organizations, users, and repositories. This tool provides detailed threat analysis with per-repository, per-issue reporting and risk scoring.
The Shai Hulud threat hunting tool scans GitHub environments for indicators of compromise (IOCs) related to the Shai Hulud supply chain attack campaign. It provides immediate detection capabilities for organizations to assess their exposure and respond to threats.
- β Multi-Target Scanning: Organizations, users, or individual repositories
- β Comprehensive Package Detection: 555 known compromised packages across 8+ ecosystems
- β Detailed Threat Reporting: Per-repository, per-issue analysis with risk scoring
- β Multiple Threat Vectors: Malicious workflows, package vulnerabilities, suspicious branches, webhook exfiltration
- β Enterprise Security: Secure token storage, input sanitization, DoS protection
- β SIEM Integration: Structured JSON output for security orchestration
- β Security Hardened: Protection against credential exposure, injection attacks, and resource exhaustion
Scans for compromised packages across multiple ecosystems:
- JavaScript/Node.js: package.json, yarn.lock, package-lock.json
- Python: requirements.txt, pyproject.toml, Pipfile, setup.py
- Go: go.mod, go.sum
- Rust: Cargo.toml, Cargo.lock
- Java: pom.xml, build.gradle
- Ruby: Gemfile
- PHP: composer.json
- Workflow Files:
.github/workflows/shai-hulud-workflow.yml - Data Exfiltration: webhook.site references in code
- Suspicious Branches: "shai-hulud" or "shai hulud" branch names
- Audit Events: Repository creation, visibility changes, push events
- π¨ CRITICAL (150+): Multiple high-severity threats
β οΈ HIGH (80-149): Single high-severity or multiple medium threats- π‘ MEDIUM (1-79): Single medium-severity threat
- β CLEAN (0): No threats detected
- Python 3.7+
requestslibrary- GitHub Personal Access Token
- Internet connectivity for GitHub API access
# 1. Download and setup
git clone https://github.com/rocklambros/shai_hulud_hunt.git
cd shai_hulud_hunt
pip install requests
# 2. Configure GitHub token
export GITHUB_TOKEN="github_pat_your_token_here"
export GITHUB_ORG="your-organization"
# 3. Run scan
python3 shai_hulud_github_hunt.py# Create virtual environment
python3 -m venv shai_hulud_env
source shai_hulud_env/bin/activate # Linux/macOS
# OR
shai_hulud_env\Scripts\activate.bat # Windows
# Install and run
git clone https://github.com/rocklambros/shai_hulud_hunt.git
cd shai_hulud_hunt
pip install requests
python3 shai_hulud_github_hunt.py# Build and run with Docker
docker build -t shai-hulud-hunt .
docker run -e GITHUB_TOKEN=$GITHUB_TOKEN -e GITHUB_ORG=$GITHUB_ORG shai-hulud-hunt-
Navigate to GitHub Settings
- Go to https://github.com/settings/tokens
- Click "Generate new token" β "Fine-grained tokens" (recommended)
-
Configure Token Permissions
For Public Repository Scanning:
- β
Contents: Read - β
Metadata: Read
For Private Repository & Organization Scanning:
- β
Contents: Read - β
Metadata: Read - β
Actions: Read(for workflow detection)
For Enterprise Audit Log Access (Optional):
- β
Administration: Read(for audit logs)
- β
-
Generate and Secure Token
- Click "Generate token"
- Copy token immediately (cannot be viewed again)
- Store securely in password manager
# Add to ~/.bashrc or ~/.zshrc for persistence
export GITHUB_TOKEN="github_pat_your_token_here"
export GITHUB_ORG="your-organization-name"
# Apply changes
source ~/.bashrc# Set for current session
$env:GITHUB_TOKEN="github_pat_your_token_here"
$env:GITHUB_ORG="your-organization-name"
# Set permanently (requires restart)
[Environment]::SetEnvironmentVariable("GITHUB_TOKEN", "github_pat_your_token_here", "User")| Variable | Description | Required |
|---|---|---|
GITHUB_TOKEN |
GitHub Personal Access Token | Yes |
GITHUB_ORG |
Target organization name | Optional* |
GITHUB_USER |
Target username | Optional* |
GITHUB_TARGET |
Target repository (owner/repo) | Optional* |
*At least one target must be specified via environment variable or interactive prompt
Run without environment variables for guided setup:
python3 shai_hulud_github_hunt.pyThe tool will prompt for:
- Scan Target Type: Organization, User, or Single Repository
- Target Name: Specific organization, username, or repository
- GitHub Token: If not set in environment variables
export GITHUB_TOKEN="github_pat_your_token_here"
export GITHUB_ORG="microsoft"
python3 shai_hulud_github_hunt.pyexport GITHUB_TOKEN="github_pat_your_token_here"
export GITHUB_USER="octocat"
python3 shai_hulud_github_hunt.pyexport GITHUB_TOKEN="github_pat_your_token_here"
export GITHUB_TARGET="microsoft/vscode"
python3 shai_hulud_github_hunt.pyπ― SHAI HULUD THREAT HUNT RESULTS
============================================================
π Repositories scanned: 150
π Suspicious repositories: 2
π Malicious workflows: 1
π Webhook.site references: 3
π Compromised packages: 5
π Suspicious branches: 1
π Audit log events: 12
============================================================
π REPOSITORY: orgname/vulnerable-app
π― RISK LEVEL: π¨ CRITICAL (Score: 310)
π’ ISSUES FOUND: 4
π DETAILED ISSUES:
1. π¨ [COMPROMISED_PACKAGE] Compromised JavaScript package: @ahmedhfarag/ngx-perfect-scrollbar
π Package @ahmedhfarag/ngx-perfect-scrollbar@20.0.20 is compromised (Shai Hulud campaign)
π¦ File: package.json
π Ecosystem: JavaScript/Node.js
π View File: https://github.com/orgname/vulnerable-app/blob/main/package.json
Complete findings in SIEM-ready JSON format at the end of output for integration with security tools.
The tool includes enterprise-grade security protections:
- β Secure Token Storage: XOR obfuscation prevents credential exposure in memory dumps
- β Input Sanitization: Comprehensive validation protects against injection attacks
- β Token Scope Validation: Automatic checking for least privilege compliance
- β DoS Protection: Resource limits prevent attacks on large organizations
- β Security Logging: Comprehensive audit trail for compliance and incident response
- β Defensive Programming: API timeouts, rate limiting, error sanitization
- Secure Storage: Tokens stored with XOR obfuscation in memory
- Automatic Validation: Pre-scan token scope and permission checking
- Least Privilege: Warns about excessive permissions (admin:org, etc.)
- Never commit tokens to version control
- Use environment variables or secure credential management
- Rotate tokens regularly
- Repository Limits: Maximum 1000 repositories per scan
- Branch Limits: Maximum 100 branches per repository
- API Rate Limiting: 60 calls per minute with automatic backoff
- Timeout Protection: 15-second timeout on all API requests
- Tool makes HTTPS requests to api.github.com only
- No data is transmitted to third parties
- All scanning is read-only (no modifications made)
- Input sanitization prevents malicious repository data processing
- Local Processing: All analysis performed locally, no external data transmission
- Audit Trail: Comprehensive security event logging for compliance
- Data Sanitization: Sensitive information removed from error messages
- Secure Defaults: Security-first configuration throughout
# Set proxy environment variables
export HTTP_PROXY=http://proxy.company.com:8080
export HTTPS_PROXY=http://proxy.company.com:8080
# For authenticated proxies
export HTTP_PROXY=http://username:password@proxy.company.com:8080
export HTTPS_PROXY=http://username:password@proxy.company.com:8080# Add CA certificate to Python requests
export REQUESTS_CA_BUNDLE=/path/to/company-ca-bundle.crt
# Or disable SSL verification (NOT recommended for production)
export PYTHONHTTPSVERIFY=0The tool uses compromised_packages.txt containing 555 known compromised packages. To update:
- Add new package identifiers in
package@versionformat - One package per line
- Comments supported with
#prefix
The tool implements intelligent rate limiting:
- Automatic retry with exponential backoff
- 60 API calls per minute maximum
- 15-second timeout on all requests
- Polite delays between different API endpoint calls
Problem: 401 Unauthorized or insufficient permissions Solution: Verify token has required scopes:
# The tool now includes automatic token validation
export GITHUB_TOKEN="github_pat_your_token_here"
python3 shai_hulud_github_hunt.py
# Output includes security validation:
# π Validating GitHub token...
# β
Token validation successful
# β οΈ Warning: Token has excessive scope 'admin:org' - not required for scanningProblem: HTTP 429 errors or rate limit warnings Solution: Tool implements automatic rate limiting and retry logic
Problem: API returns 403 Forbidden during package scanning Solution: Tool automatically uses Repository Contents API instead of Search API
# Test GitHub API connectivity
curl -H "Authorization: Bearer $GITHUB_TOKEN" https://api.github.com/userProblem: Package scanning reports 0 packages but repositories contain package files
Solution: Check that compromised_packages.txt exists and contains package data
pip install requests
# If using system Python on Linux
sudo apt-get install python3-pip # Ubuntu/Debian
pip3 install requestschmod +x shai_hulud_github_hunt.py
# Or run with python3 explicitly
python3 shai_hulud_github_hunt.py- Proxy Configuration: Set HTTP_PROXY/HTTPS_PROXY environment variables
- Firewall Rules: Ensure outbound HTTPS access to api.github.com
- SSL Certificates: Configure REQUESTS_CA_BUNDLE if needed
- Small organizations (<10 repos): 1-2 minutes
- Medium organizations (10-100 repos): 5-15 minutes
- Large organizations (100+ repos): 15+ minutes
- Memory: <50MB typical usage (512MB limit enforced)
- Network: ~1KB per API call, depends on repository count
- CPU: Minimal, I/O bound workload
# Consider running in background
nohup python3 shai_hulud_github_hunt.py > scan_results.log 2>&1 &
# Monitor progress
tail -f scan_results.logThe tool outputs structured JSON at the end of each scan for easy integration with security tools:
# Extract JSON findings and send to Splunk
python3 shai_hulud_github_hunt.py > /tmp/scan_output.txt 2>&1
grep -A 999999 "RAW JSON FINDINGS:" /tmp/scan_output.txt | tail -n +2 > /tmp/scan_results.json
# Send to Splunk via HTTP Event Collector
curl -k -X POST https://splunk.company.com:8088/services/collector \
-H "Authorization: Splunk your-hec-token" \
-H "Content-Type: application/json" \
-d @/tmp/scan_results.json#!/bin/bash
# automated_scan.sh - Daily scanning with alerting
export GITHUB_TOKEN="github_pat_your_token_here"
export GITHUB_ORG="your-org"
# Run scan
python3 shai_hulud_github_hunt.py > scan_results.txt 2>&1
# Check for threats and alert
CRITICAL_COUNT=$(grep -c "π¨ CRITICAL" scan_results.txt || echo "0")
if [ "$CRITICAL_COUNT" -gt 0 ]; then
# Send alert notification
echo "π¨ $CRITICAL_COUNT critical threats detected in $GITHUB_ORG" | \
mail -s "Shai Hulud Critical Alert" security-team@company.com
fi# GitHub Actions example
name: Shai Hulud Security Scan
on:
schedule:
- cron: '0 6 * * 1' # Weekly Monday 6 AM
workflow_dispatch:
jobs:
security-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Setup Python
uses: actions/setup-python@v4
with:
python-version: '3.9'
- name: Install dependencies
run: pip install requests
- name: Run secure scan
env:
GITHUB_TOKEN: ${{ secrets.SECURITY_SCAN_TOKEN }}
GITHUB_ORG: ${{ github.repository_owner }}
run: python3 shai_hulud_github_hunt.py > scan_results.json
- name: Upload results
uses: actions/upload-artifact@v4
with:
name: security-scan-results
path: scan_results.jsongit clone https://github.com/rocklambros/shai_hulud_hunt.git
cd shai_hulud_hunt
# Install development dependencies
pip install requests
# Run syntax check
python3 -m py_compile shai_hulud_github_hunt.py
# Test with small repository
export GITHUB_TARGET="octocat/Hello-World"
python3 shai_hulud_github_hunt.py- Update
package_filesdictionary inscan_repository_packages() - Add parsing logic in
parse_package_file_content() - Test with sample package files
- Update documentation
- Follow PEP 8 Python style guidelines
- Use descriptive variable names
- Add docstrings for functions
- Maintain existing error handling patterns
This project is licensed under the MIT License - see the LICENSE file for details.
This tool is provided for legitimate cybersecurity purposes only. Users are responsible for:
- Ensuring proper authorization before scanning GitHub resources
- Complying with applicable laws and regulations
- Respecting GitHub's Terms of Service and API rate limits
- Protecting any sensitive information discovered during scanning
For issues, questions, or contributions:
- Issues: Open a GitHub issue with detailed reproduction steps
- Documentation: Check this README and inline code documentation
- Security Issues: Report privately to maintainers
- GitHub API documentation and best practices
- Cybersecurity research community for IOC identification
- Open source security tools for inspiration and patterns
Generated with Claude Code | Last Updated: 2025-09-17