IOC Radar
TLP:WHITE1 IOC

Shai-Hulud Malware In-Depth Analysis: Open Source Means Loss of Control?

SL
SlowMist
Published May 14, 2026Original Report

Threat Actors

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYSandwormINFRASTRUCTUREunknownCAPABILITYunknownVICTIMunknown
Adversary(1)
Infrastructure
Capability
Victim

Attack Flow8 steps · MITRE ATT&CK mapped

Initial AccessTA0001·T1078
1/8
Compromise Accounts
ActionSpread via compromised accounts
Threat actors used compromised GitHub accounts to spread the Shai-Hulud malware.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise1

TypeIndicatorConfidenceScoreFirst Seen
SHA1d446803f4c3bc116263faa3499a1d3f95b2825de
exploitfile-hashintel-blog
Medium
53
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph1 total IOCs
SHA1
SHA11Actors1REPORTShai-Hulud Malware In-DeptSandworm
scroll to zoom · drag to pan · click IOC to open