[rule]
description = """
Detects creation of a Bun runtime binary (bun/bun.exe) by common download, archive, shell, or Node.js processes,
followed within one minute by execution of Bun as a child or descendant of Node.js. Multiple npm supply chain campaigns
(including Mini Shai-Hulud / Team PCP style attacks) use a Node install/preinstall script to fetch a standalone Bun
binary, then invoke Bun to run a heavily obfuscated second-stage payload and evade Node-focused monitoring.
"""
id = "8d439fa0-a386-4dc8-a5ce-daa669a80fc5"
license = "Elastic License v2"
name = "Bun Runtime Dropped and Executed via Node.js"
os_list = ["macos"]
reference = [
"https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared",
"https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain",
"https://www.elastic.co/security-labs/threat-command/axios-one-rat-to-rule-them-all",
]
version = "1.0.1"
query = '''
sequence by user.id with maxspan=1m
[file where event.type == "creation" and
process.name : (
"curl", "curl.exe",
"wget", "wget.exe",
"powershell.exe", "pwsh.exe",
"node", "node.exe",
"tar", "tar.exe",
"unzip", "unzip.exe"
) and
file.name : ("bun", "bun.exe")]
[process where event.type == "start" and event.action in ("exec", "start") and
process.name : ("bun", "bun.exe") and
(
process.parent.name : ("node", "node.exe") or
descendant of [
process where event.action in ("start", "exec") and process.name : ("node", "node.exe")
]
) and
not process.args in ("--revision", "--version", "/builds/stovetv-backend/partners-chat-fe/scripts/update-app-version.mjs")]
'''
min_endpoint_version = "7.15.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 1
tree = true
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1195"
name = "Supply Chain Compromise"
reference = "https://attack.mitre.org/techniques/T1195/"
[[threat.technique.subtechnique]]
id = "T1195.002"
name = "Compromise Software Supply Chain"
reference = "https://attack.mitre.org/techniques/T1195/002/"
[threat.tactic]
id = "TA0001"
name = "Initial Access"
reference = "https://attack.mitre.org/tactics/TA0001/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1059"
name = "Command and Scripting Interpreter"
reference = "https://attack.mitre.org/techniques/T1059/"
[[threat.technique.subtechnique]]
id = "T1059.007"
name = "JavaScript"
reference = "https://attack.mitre.org/techniques/T1059/007/"
[threat.tactic]
id = "TA0002"
name = "Execution"
reference = "https://attack.mitre.org/tactics/TA0002/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1105"
name = "Ingress Tool Transfer"
reference = "https://attack.mitre.org/techniques/T1105/"
[threat.tactic]
id = "TA0011"
name = "Command and Control"
reference = "https://attack.mitre.org/tactics/TA0011/"
[internal]
min_endpoint_version = "7.15.0"