The Shai-Hulud v2 Maven Central Supply Chain Attack

Updated 5 Oct 2026 · Incident date 24 Nov 2025 · Maven

Packageorg.mvnpm:posthog-node 4.18.0 -> 4.18.1
Filesetup_bun.js

The Maven package org.mvnpm:posthog-node 4.18.1 carried the Shai-Hulud v2 worm. It was an automatic Maven copy of a compromised npm package. PostHog did not publish it.

A clean 4.18.0 of the same coordinates existed. Version 4.18.1 added two script files that install a runtime and run a large hidden payload to steal credentials. Maven Central purged the mirrored copies on 25 November 2025.

What happened

The Shai-Hulud v2 npm campaign crossed into Java when mvnpm rebuilt a poisoned npm package as a Maven artifact. The Hacker News reports that org.mvnpm:posthog-node:4.18.1 was the only Java package found with Shai-Hulud v2 parts at the time. The campaign itself began on 24 November 2025, and Socket confirmed the spill into the Java and Maven ecosystem on 25 November.

The mvnpm coordinates use an automated process that rebuilds npm packages as Maven artifacts. That process converted the compromised PostHog npm package without manual review. The Maven Central copy was not published by PostHog.

The artifact held two components. The first is setup_bun.js, a loader. The second is bun_environment.js, a payload of about 10 MB that is heavily obfuscated. The loader downloads the Bun runtime, caches it, and starts the payload in a detached background process with the flag POSTINSTALL_BG=1 and all output suppressed.

The payload steals system information, GitHub tokens, environment variables, and cloud secrets for AWS, GCP and Azure. It also downloads the TruffleHog tool to scan the home directory for hardcoded secrets and pulls GitHub Actions secrets. If it finds a valid npm token, it injects the malicious files into other packages from that account, raises the patch version and republishes them.

The attack began on npm. Over 500 packages were hit across scopes such as @zapier, @asyncapi, @postman, @posthog and @ensdomains, according to Socket. The Hacker News puts the count above 830. PostHog confirmed that the first access came from abuse of a pull_request_target GitHub Actions workflow.

Affected versions

The Hacker News names 4.18.1 as the only Java package found with the worm at the time of writing. Maven Central stated that all mirrored copies were purged as of 25 November 2025, 22:44 UTC. A project that resolved 4.18.1 before that time still holds a bad copy in its local cache.

Indicators of compromise

How to check

Search your Maven dependency tree and local repository for the bad version. This command only reads files and does not run the package.

mvn dependency:tree | grep posthog-node

Then look in the local Maven cache for the version directory.

ls ~/.m2/repository/org/mvnpm/posthog-node/

If 4.18.1 appears, treat every machine and CI runner that built the project as exposed. Check GitHub for repositories described as Sha1-Hulud: The Second Coming.

Vigilance compares the version you trust with a new one. For this release, it will report new script files that install a runtime and execute a large decoded blob.

What to do now

  1. Remove org.mvnpm:posthog-node 4.18.1 and pin 4.18.0 or a later clean release.
  2. Delete the cached artifact and any node_modules folders on affected machines.
  3. Rotate all API keys, tokens and passwords that the build machine can reach, including GitHub, npm and cloud keys.
  4. Review GitHub for repositories that match the campaign description.
  5. Review the GitHub Actions secrets of any repository built on an affected machine.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old posthog-node-4.18.0 --new posthog-node-4.18.1
files scanned: 82 (2 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   setup_bun.js
           It runs a command on its own when it is installed, reads saved passwords and access keys and runs other programs.

Frequently asked questions

Did Shai-Hulud v2 reach Maven Central?

Yes. The Hacker News reports that org.mvnpm:posthog-node:4.18.1 carried the Shai-Hulud v2 loader and payload. It was an automatic Maven rebuild of the compromised npm package. Maven Central purged the mirrored copies on 25 November 2025.

Did PostHog publish the bad Maven package?

No. The Hacker News states that the Maven Central package was not published by PostHog. The mvnpm process rebuilt the npm package as a Maven artifact.

Sources

  1. socket.dev/blog/shai-hulud-strikes-again-v2
  2. thehackernews.com/2025/11/shai-hulud-v2-campaign-spreads-from-npm.html
  3. wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-supply-chain-attack

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free