


Perceptive Security
SOC/SIEM Consultancy

Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of Secrets
Published:
26 November 2025 at 18:08:00
Alert date:
5 December 2025 at 08:03:23
Source:
thehackernews.com

The Shai-Hulud supply chain attack has evolved into its second wave, expanding from the npm registry to the Maven ecosystem. The campaign has compromised over 830 packages in the npm registry and has now infected at least one Maven Central package (org.mvnpm:posthog-node:4.18.1). The attack continues to use the same components: the 'setup_bun.js' loader and the main payload 'bun_environment.js'. This cross-platform expansion demonstrates the campaign's sophistication and ability to target multiple package management ecosystems, potentially exposing thousands of secrets from affected environments.
Technical details
Mitigation steps:
Affected products:
npm
Maven Central
posthog-node
Related links:
Related CVE's:
Related threat actors:
IOC's:
org.mvnpm:posthog-node:4.18.1, setup_bun.js, bun_environment.js
This article was created with the assistance of AI technology by Perceptive.