avatar

Matthias Chladek

@msxreminds
0 followers0 downloads12 copies0 likes18 views

1 detection

Detects execution artifacts of the ChainDrop (Shai-Hulud) npm supply-chain campaign on endpoints. The campaign abuses npm `preinstall` lifecycle hooks in compromised packages to run `setup.mjs`, which downloads a Bun runtime and executes the `Math_Symbol.js` / `math_init.js` payload for credential and token theft.


The query matches on two signals:



- **CampaignArtifact (High)** — the filenames `setup.mjs`, `Math_Symbol.js` or `math_init.js` appearing in either the process or parent process command line. Effectively unique to this campaign; `setup.mjs` has occasional legitimate use and is verified via the repository path.

- **BunFromNodeModules (Contextual)** — `bun.exe` spawning child processes from a `node_modules` path. Covers the case where `setup.mjs` downloads and invokes Bun internally, leaving no URL or version string in process telemetry. Also survives a variant renaming the payload files.



Set `IncludeBunBranch = false` to drop the contextual branch; the remaining artifact branches are low-volume and suitable for scheduled execution. Leave it enabled for manual hunts. Baseline Bun usage across the developer estate before scheduling with the branch on.


**Coverage limits:** endpoint execution only. Does not cover the initial package download, GitHub Actions workflow injection, or exfiltration to attacker infrastructure. Pair with the SHA256 file-hash query for pre-execution detection.
avatar
Matthias Chladek@msxreminds
avatar
Detections.ai Community
2 months ago
12018