URL has been copied successfully!
Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets

The second wave of the Shai-Hulud supply chain attack has spilled over to the Maven ecosystem after compromising more than 830 packages in the npm registry.The Socket Research Team said it identified a Maven Central package named org.mvnpm:posthog-node:4.18.1 that embeds the same two components associated with Sha1-Hulud: the “setup_bun.js” loader and the main payload “bun_environment.js.””

First seen on thehackernews.com

Jump to article: thehackernews.com/2025/11/shai-hulud-v2-campaign-spreads-from-npm.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link