krebson security
Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’
26 November 2025
graham-cluley-banner-jpg
Smashing Security podcast #445: The hack that brought back the zombie apocalypse
27 November 2025

Resources

Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets

The second wave of the Shai-Hulud supply chain attack has spilled over to the Maven ecosystem after compromising more than 830 packages in the npm registry.
The Socket Research Team said it identified a Maven Central package named org.mvnpm:posthog-node:4.18.1 that embeds the same two components associated with Sha1-Hulud: the “setup_bun.js” loader and the main payload “bun_environment.js.”

Related resources