Join our Newsletter — 33% off our NHI Course

Should teams prioritise JIT access or secrets rotation first when defending against worms like Shai Hulud?

Prioritise JIT access first when the immediate issue is durable, reusable credentials that can be replayed across systems. Rotation still matters, but it does not remove the standing access window that lets a worm move from one compromised environment to another before anyone notices.

Why JIT access usually beats secrets rotation against a self-propagating worm

Worms like Shai Hulud do not just steal a credential once, they try to reuse it to keep moving. JIT access changes the default from standing permission to time-bound access, which sharply reduces the number of credentials a worm can replay. Rotation still matters, but if access remains always-on, the attacker can often act before rotation completes.

That difference matters most when the compromised asset is a durable secret, such as an API key, token, or long-lived service credential. If the access path is still valid across systems, rotating one secret may only close one door while leaving other standing credentials available for propagation.

JIT access is therefore a control over standing privilege, not just a convenience feature. It shortens the usable window, forces approval or activation at the point of need, and makes silent reuse much harder for malware that depends on persistence and lateral movement.

Why rotation remains necessary, but is rarely the first move

secrets rotation addresses compromise of the secret itself. It is essential when a key, token, or password may already be exposed, especially in CI/CD, repositories, or logs. But rotation is not a substitute for access design, because a worm can exploit any still-valid standing credential before the rotated value propagates everywhere it is embedded.

That is why JIT access and rotation solve different problems. JIT reduces the blast radius by removing unnecessary standing access, while rotation invalidates material that may already be known to an attacker. In practice, the highest priority is to eliminate reusable access paths first, then rotate what remains exposed or suspect.

For teams managing broad privilege estates, Privileged Access Management is the control plane that usually ties those decisions together, because it combines activation, session oversight, vaulting, and break-glass exceptions. Without that control layer, rotation becomes a recurring cleanup task rather than a structural reduction in attack surface.

When the exposed material is itself the problem, secrets sprawl is what makes worms dangerous: one leaked value often exists in multiple copies, stores, and pipelines. In that situation, rotation must be paired with discovery and revocation discipline, or the worm simply pivots to the next copy.

How to decide what to fix first in a worm scenario

The decision hinges on whether the worm can still authenticate and move. If the answer is yes, prioritise the control that removes standing access and narrows activation windows. If the compromise is limited to a single credential with no usable standing path, rotation can take the lead because it directly invalidates the attacker’s replay option.

That is why a secretless or short-lived credential model is more resilient than periodic clean-up alone. The less often a secret exists in reusable form, the less value a worm gets from stealing it, and the less time defenders spend chasing dispersed copies.

Teams should also treat build and publishing workflows differently from human admin access. A worm that lands in software delivery can often chain from one credentialed system to another, so the immediate question is not only “is the secret rotated?” but “can any standing credential still authenticate from one environment into the next?”

Risk and Threat Considerations

Self-propagating malware benefits from any reusable access path, because reuse turns a single compromise into repeated authentication attempts across systems. The risk is highest when the same secret, token, or privilege can be replayed before defenders finish rotation or investigation.

Failure mechanism: Standing access remains valid long enough for the worm to authenticate again, move laterally, or harvest additional secrets from connected systems before the rotated credential fully displaces all copies.

Impact: Containment slows down, blast radius expands, and one compromised environment can become a launch point for many others.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-07 — Long-Lived Secrets Long-lived secrets are the replayable material worms exploit for propagation.
NHI-01 — Improper Offboarding Dormant standing access and stale credentials keep attack paths alive after compromise.
NHI-05 — Overprivileged NHI Excess privilege increases the blast radius once a worm captures one credential.
Recommendation — Replace long-lived secrets with short-lived credentials and revoke exposed values immediately. Remove stale access paths so compromised credentials cannot keep being reused. Reduce privilege to limit what a stolen credential can reach.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Credential lifecycle control is central when deciding whether rotation can stop reuse.
AC-6 — Least Privilege Standing access creates propagation opportunities that least privilege would narrow.
Recommendation — Rotate and invalidate authenticators on exposure or compromise. Limit permissions so compromised access cannot spread broadly.
CIS Controls v8 CIS-5 — Account Management Account lifecycle and removal of stale access are key to stopping worm reuse.
CIS-6 — Access Control Management JIT access is an access-control decision that reduces standing exposure.
Recommendation — Deactivate unnecessary accounts and access paths before attackers can reuse them. Enforce just-in-time access for privileged actions.
OWASP ASVS V8 — Authorization Authorization scope determines whether a stolen credential can move laterally or act broadly.
V6 — Authentication Rotation and replay resistance are authentication concerns when secrets are stolen.
Recommendation — Constrain authorization so compromised access cannot reach unrelated systems. Use strong authentication patterns that reduce secret replay value.

Practitioner Guidance

What to prioritise: Start by removing standing access paths that let the malware reuse the same authority across systems. If a credential is both exposed and broadly reusable, treat access reduction as the first containment move and rotation as the follow-on cleanup.

What to verify: Confirm whether the credential is present in multiple pipelines, runners, vaults, or configuration stores. If it is, rotating one copy without invalidating the rest will not materially change the worm’s movement options.

Practitioner takeaway: In worm defence, the first win is usually shrinking the number of places an attacker can authenticate from, because that immediately constrains propagation; rotation is essential, but it is the second control that finishes the job.