Diamond Member ThaHaka 0 Posted November 26, 2025 Diamond Member Share Posted November 26, 2025 This is the hidden content, please Sign In or Sign Up The second wave of the Shai-Hulud supply chain attack has spilled over to the Maven ecosystem after compromising more than 830 packages in the npm registry. The Socket Research Team said it identified a Maven Central package named org.mvnpm:posthog-node:4.18.1 that embeds the same two components associated with Sha1-Hulud: the "setup_bun.js" loader and the main payload "bun_environment.js." " This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/290336-h4ckn3wsshai-hulud-v2-campaign-spreads-from-npm-to-maven-exposing-thousands-of-secrets/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.