
Matthias Chladek
@msxreminds0 followers0 downloads12 copies0 likes18 views
1 detection
Filters
Last updated
All Time
Detection languages
1
Platforms
1
MITRE Techniques
1
1
1
Detects execution artifacts of the ChainDrop (Shai-Hulud) npm supply-chain campaign on endpoints. The campaign abuses npm `preinstall` lifecycle hooks in compromised packages to run `setup.mjs`, which downloads a Bun runtime and executes the `Math_Symbol.js` / `math_init.js` payload for credential and token theft.
The query matches on two signals:
- **CampaignArtifact (High)** — the filenames `setup.mjs`, `Math_Symbol.js` or `math_init.js` appearing in either the process or parent process command line. Effectively unique to this campaign; `setup.mjs` has occasional legitimate use and is verified via the repository path.
- **BunFromNodeModules (Contextual)** — `bun.exe` spawning child processes from a `node_modules` path. Covers the case where `setup.mjs` downloads and invokes Bun internally, leaving no URL or version string in process telemetry. Also survives a variant renaming the payload files.
Set `IncludeBunBranch = false` to drop the contextual branch; the remaining artifact branches are low-volume and suitable for scheduled execution. Leave it enabled for manual hunts. Baseline Bun usage across the developer estate before scheduling with the branch on.
**Coverage limits:** endpoint execution only. Does not cover the initial package download, GitHub Actions workflow injection, or exfiltration to attacker infrastructure. Pair with the SHA256 file-hash query for pre-execution detection.
The query matches on two signals:
- **CampaignArtifact (High)** — the filenames `setup.mjs`, `Math_Symbol.js` or `math_init.js` appearing in either the process or parent process command line. Effectively unique to this campaign; `setup.mjs` has occasional legitimate use and is verified via the repository path.
- **BunFromNodeModules (Contextual)** — `bun.exe` spawning child processes from a `node_modules` path. Covers the case where `setup.mjs` downloads and invokes Bun internally, leaving no URL or version string in process telemetry. Also survives a variant renaming the payload files.
Set `IncludeBunBranch = false` to drop the contextual branch; the remaining artifact branches are low-volume and suitable for scheduled execution. Leave it enabled for manual hunts. Baseline Bun usage across the developer estate before scheduling with the branch on.
**Coverage limits:** endpoint execution only. Does not cover the initial package download, GitHub Actions workflow injection, or exfiltration to attacker infrastructure. Pair with the SHA256 file-hash query for pre-execution detection.
