National Cyber Warfare Foundation (NCWF)

Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of Secrets


0 user ratings
2025-11-27 04:18:02
milo
Blue Team (CND)
The second wave of the Shai-Hulud supply chain attack has spilled over to the Maven ecosystem after compromising more than 830 packages in the npm registry.
The Socket Research Team said it identified a Maven Central package named org.mvnpm:posthog-node:4.18.1 that embeds the same two components associated with Sha1-Hulud: the "setup_bun.js" loader and the main payload "bun_environment.js." The



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/11/shai-hulud-v2-campaign-spreads-from-npm.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.