top of page
perceptive_background_267k.jpg

Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of Secrets

Published:

26 november 2025 om 18:08:00

Alert date:

5 december 2025 om 08:03:23

Source:

thehackernews.com

Click to open the original link from this advisory

The Shai-Hulud supply chain attack has evolved into its second wave, expanding from the npm registry to the Maven ecosystem. The campaign has compromised over 830 packages in the npm registry and has now infected at least one Maven Central package (org.mvnpm:posthog-node:4.18.1). The attack continues to use the same components: the 'setup_bun.js' loader and the main payload 'bun_environment.js'. This cross-platform expansion demonstrates the campaign's sophistication and ability to target multiple package management ecosystems, potentially exposing thousands of secrets from affected environments.

Technical details

Mitigation steps:

Affected products:

npm
Maven Central
posthog-node

Related links:

Related CVE's:

Related threat actors:

IOC's:

org.mvnpm:posthog-node:4.18.1, setup_bun.js, bun_environment.js

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page