Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of Secrets
After compromising over 830 packages in the npm registry, the second wave of the Shai-Hulud supply chain attack has spread to the Maven ecosystem.
The Maven Central package org.mvnpm:posthog-node:4.18.1, according to the Socket Research Team, has the same two elements linked to Sha1-Hulud: the loader "setup_bun.js" and the primary payload "bun_environment.js." The Hacker News was informed by the company that the sole Java package found thus far was org.mvnpm:posthog-node:4.18.1.
According to a Tuesday update from the cybersecurity firm, the PostHog project has compromised releases in both the JavaScript/npm and Java/Maven ecosystems, powered by the identical Shai Hulud v2 payload.
It is important to note that PostHog does not publish the Maven Central package. Instead, an automat...





