{"rewrite":{"id":"r_df4341dcf77bcfc94dcd917b","clusterId":"c_aaaba5daf5b5251b816b1817","slug":"shai-hulud-worm-moves-from-ci-cd-pipeline-into-aws-cloud-data","model":"deepseek-v4-flash:free","headline":"Shai Hulud Worm Moves From CI/CD Pipeline Into AWS Cloud Data","summary":"Fortinet's FortiCNAPP helped identify an AWS environment compromised by the Shai Hulud software worm, which targets npm and PyPI packages. Investigators found attackers used a Jenkins EC2 instance role from an external IP, escalated privileges, altered security groups, and extracted data from Amazon Redshift. The campaign, attributed to TeamPCP, collected credentials from build environments.","whyItMatters":"The incident shows CI/CD pipeline identities can become production cloud identities, turning build infrastructure into a direct path to cloud data theft.","webCardHtml":"\u003cp\u003eFortinet\u0026#39;s FortiCNAPP assisted in identifying an AWS environment affected by the Shai Hulud worm in May 2026. Investigators found evidence of ongoing access to a Jenkins runner matching the worm\u0026#39;s credential collection patterns. Attackers used the Jenkins EC2 instance role from an external IP, created an IAM user named cloudops-monitor with admin rights, modified security groups, and used the Redshift Data API to run queries.\u003c/p\u003e\u003cp\u003eThe worm, named after the sandworm from Dune, embeds malicious packages that run during installation or CI job execution. It collects package registry tokens, GitHub tokens, AWS credentials, Kubernetes secrets, and SSH keys. Recent variants abuse GitHub Actions\u0026#39; trusted OIDC publishing to generate artifacts that appear legitimately certified.\u003c/p\u003e","blueskyPost":"Shai Hulud's move from CI/CD to AWS shows the attack path: build systems as a pivot into cloud data. Fortinet's FortiCNAPP caught it, but the escalation from a Jenkins role to Redshift extraction is the part to watch.","twitterPost":"Shai Hulud's CI/CD-to-AWS path: Jenkins role, privilege escalation, Redshift data theft. Build environments are the new perimeter.","threadsPost":"Shai Hulud's campaign is a reminder that CI/CD pipelines are a gateway to cloud data. Attackers used a Jenkins EC2 instance role, escalated privileges, and pulled data from Redshift. Fortinet's FortiCNAPP identified it, but the pattern shows build environments as a weak link.","newsletterBlurb":"Fortinet's FortiCNAPP helped identify an AWS environment compromised by the Shai Hulud worm, which moved from a Jenkins runner to cloud data theft. Attackers escalated privileges and extracted data from Amazon Redshift.","attributionJson":"[{\"source\":\"ASCII.jp\",\"url\":\"https://ascii.jp/elem/000/004/427/4427253/?rss\",\"title\":\"CI/CDパイプラインからクラウドへと侵入するソフトウェアワームを特定\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":5955,"outputTokens":528,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1787129624,"createdAt":"2026-08-19T08:46:23.000Z","publishedAt":"2026-08-19T08:46:44.000Z","updatedAt":"2026-08-19T08:46:23.000Z"},"cluster":{"id":"c_aaaba5daf5b5251b816b1817","canonicalTitle":"CI/CDパイプラインからクラウドへと侵入するソフトウェアワームを特定","representativeArticleId":"a_40445500b1b92d2c3c3c0a01","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-08-19T08:00:00.000Z","lastSeenAt":"2026-08-19T08:00:00.000Z","updatedAt":"2026-08-19T08:46:46.000Z"},"attribution":[{"source":"ASCII.jp","url":"https://ascii.jp/elem/000/004/427/4427253/?rss","title":"CI/CDパイプラインからクラウドへと侵入するソフトウェアワームを特定"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
