After compromising over 830 packages in the npm registry, the second wave of the Shai-Hulud supply chain attack has spread to the Maven ecosystem.
The Maven Central package org.mvnpm:posthog-node:4.18.1, according to the Socket Research Team, has the same two elements linked to Sha1-Hulud: the loader “setup_bun.js” and the primary payload “bun_environment.js.” The Hacker News was informed by the company that the sole Java package found thus far was org.mvnpm:posthog-node:4.18.1.
According to a Tuesday update from the cybersecurity firm, the PostHog project has compromised releases in both the JavaScript/npm and Java/Maven ecosystems, powered by the identical Shai Hulud v2 payload.
It is important to note that PostHog does not publish the Maven Central package. Instead, an automated mvnpm process that rebuilds npm packages as Maven artifacts generates read more about Shai-Hulud v2 Spreads From npm to Maven as Campaign Exposes Thousands of Secrets.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
