• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Gradle Build Spawns sh -c Shell via Malicious preBuild/doLast Hook

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Nate Dunning@nateossprey
    •updated Sep 8, 2026•7•1•40

    Detects instances where a Gradle or Java build process invokes a shell (sh -c) containing suspicious build-related keywords such as 'preBuild', 'doLast', or 'tasks.all'. This pattern is commonly observed in supply chain compromises where malicious code is injected into build scripts to execute hidden payloads during the compilation phase.

    Sigma

    Tags

    T1195.002 - Compromise Software Supply ChainT1059 - Command and Scripting InterpreterT1059.004 - Unix ShellT1027 - Obfuscated Files or InformationTA0002 - ExecutionTA0005 - StealthProcess CreationCommand ExecutionScript ExecutionLinuxLinux Syslogattack.t1195.002attack.t1554attack.t1059attack.t1059.004attack.t1027

    Found in

    • XCSSET in a Flutter Package, First Supply Chain Attack on Pub.dev EcosystemLast updated Sep 9, 2026
    • First Supply Chain Attack on Pub.dev EcosystemLast updated Sep 9, 2026
    • First Supply Chain Attack on Pub.dev EcosystemLast updated Sep 8, 2026
    • First Supply Chain Attack on Pub.dev EcosystemLast updated Sep 8, 2026
    • First Supply Chain Attack on Pub.dev EcosystemLast updated Sep 8, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?