TruffleHog is a legitimate open-source secret-scanning tool that has been repeatedly repurposed by threat actors as a credential-harvesting utility. It is used to search filesystems, repositories, environment variables, CI/CD environments, and cloud-related configuration material for exposed secrets such as API keys, access tokens, cloud credentials, and other authentication artifacts. In malicious operations, it has been embedded into software supply-chain attacks, especially npm ecosystem compromises, where trojanized packages downloaded or invoked TruffleHog during installation to scan developer workstations and build runners for sensitive data.
The tool has been prominently associated with the Shai-Hulud and Sha1-Hulud npm worm campaigns, where attackers used it to harvest GitHub, npm, AWS, Azure, and Google Cloud credentials from local files and transient build environments. In those campaigns, TruffleHog-supported secret discovery was combined with exfiltration, abuse of stolen credentials to access cloud-hosted repositories and secret stores, malicious GitHub Actions workflow injection, and automated republishing of trojanized packages using compromised maintainer tokens. Threat reporting also notes its use in broader credential-access activity against victim environments and its inclusion as a module or downloaded component in other malware and intrusion sets, including developer-focused and DPRK-linked campaigns.
Although TruffleHog itself is not malware, in adversary hands it functions as an offensive credential-discovery and theft enabler. Its abuse is especially relevant in developer, CI/CD, and cloud environments because it can identify a wide range of credential types and materially support follow-on compromise, lateral movement, persistence through workflow abuse, and large-scale secret exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The first IP to touch the stolen keys ran TruffleHog to validate that the credentials were live. The TruffleHog user agent appears directly in CloudTrail.
“...contained nine modules enabling keylogging, credential theft, browser and cryptocurrency exfiltration, TruffleHog secrets scanner downloads, and persistence.”
23 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker deployed malware scans for sensitive credentials such as GitHub Personal Access Tokens (PATs) and cloud service API keys from AWS, GCP, and Azure.
The simulation confirmed the exact set of exfiltrated credentials: two distinct AWS key pairs with broad permissions
Кража секретов - Unsecured Credentials (T1552, Credential Access)... Атакующий с доступом к репозиторию модифицирует workflow, добавляя строки, которые экcфильтруют переменные окружения и секреты через HTTP-запросы.
5% of these repos exposed hardcoded API keys, database credentials, or sensitive configuration files
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
The first IP to touch the stolen keys ran TruffleHog to validate that the credentials were live. The attacker then enumerated IAM users, roles, Lambda functions, DynamoDB tables, CloudFormation stacks, and scanned every S3 bucket's ACL and public access configuration.
Downloads and executes Trufflehog, a legitimate security tool, to scan the entire home directory for API keys, passwords, and other secrets hidden in configuration files, source code, or git history
TruffleHog validation attempts may appear as rapid sequential API calls testing credential validity across multiple services.
Cieľom útoku je zneužiť nástroj TruffleHog na vyhľadávanie citlivých údajov, ako sú prístupové tokeny pre GitHub a cloudové služby...
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A secrets-scanning tool referenced as being used by the original Shai-Hulud attack to scan for exposed secrets.
A credential-seeking tool referenced as being covertly executed by the payload to harvest secrets from local caches and development environments.
A secret reconnaissance and scanning tool used in the described attack chain to identify exposed secrets.
A secrets-discovery tool used by the worm to harvest credentials and sensitive data from compromised environments before exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.