TruffleHog is a legitimate secret-scanning tool used to identify exposed credentials and other sensitive values in filesystems, configuration files, credential stores, environment variables, source code, and repositories. It supports detection of a broad range of token, API-key, and cloud-credential types. Threat actors, including operators of the Shai-Hulud npm supply-chain worm, have abused TruffleHog for automated credential discovery on compromised developer workstations and CI/CD environments. In those intrusions, the tool was downloaded and executed by malicious package-installation payloads to locate developer, npm, GitHub, cloud-service, and CI/CD secrets for subsequent collection and exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The first IP to touch the stolen keys ran TruffleHog to validate that the credentials were live. The TruffleHog user agent appears directly in CloudTrail.
“...contained nine modules enabling keylogging, credential theft, browser and cryptocurrency exfiltration, TruffleHog secrets scanner downloads, and persistence.”
22 distinct techniques documented for this family, organized by ATT&CK tactic.
“Used GitHub access tokens stolen from TruffleHog to authenticate to GitHub API and enumerate repositories accessible to the victim.”
“Shai-Hulud can self-replicate and steal credentials, tokens, and repository secrets; GitHub access tokens, Continuous Integration (CI)/Continuous Delivery (CD) pipeline secrets.”
The simulation confirmed the exact set of exfiltrated credentials: two distinct AWS key pairs with broad permissions
From there the group reached a large BigQuery instance, used the secret-scanning tool TruffleHog to find further credentials.
«Конфигурации IaC … с hardcoded secrets», «Скрипты деплоя с токенами CI/CD», «Файлы .env и .config», «Jupyter Notebook с API-ключами», «SSH-ключи и сертификаты, захваченные git add .»
The first IP to touch the stolen keys ran TruffleHog to validate that the credentials were live. The attacker then enumerated IAM users, roles, Lambda functions, DynamoDB tables, CloudFormation stacks, and scanned every S3 bucket's ACL and public access configuration.
the malware runs these tools against the compromised server's filesystem, including: Git Repositories... Directories: /tmp, /var/www, /opt, /etc , and user home directories.
TruffleHog validation attempts may appear as rapid sequential API calls testing credential validity across multiple services.
Cieľom útoku je zneužiť nástroj TruffleHog na vyhľadávanie citlivých údajov... a odoslať ich na server pod kontrolou útočníka.
creates GitHub actions for data exfiltration through webhook sites... The malware employed dual exfiltration channels, creating dedicated GitHub repositories and implementing GitHub Actions workflows with webhook endpoints, while encoding sensitive data in GitHub Actions logs.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used by Shai-Hulud after compromise to scan local filesystems and repositories for secrets, keys, and other sensitive data, then deleted to reduce forensic artifacts.
A secrets-scanning tool referenced as being used by the original Shai-Hulud attack to scan for exposed secrets.
A credential-seeking tool referenced as being covertly executed by the payload to harvest secrets from local caches and development environments.
A secret reconnaissance and scanning tool used in the described attack chain to identify exposed secrets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.