HomeSecurityShai-Hulud v2 campaign expands from npm to Maven

Shai-Hulud v2 campaign expands from npm to Maven

The second wave of the Shai-Hulud supply chain attack has expanded to the Maven ecosystem after more than 830 packages in the npm registry were compromised.

See also: New version of Shai-Hulud worm spreads via npm, GitHub

Shai-Hulud Maven

The Socket identified a Maven Central named org.mvnpm:posthog-node:4.18.1 that incorporates the same two components associated with Shai-Hulud: the “setup_bun.js” loader and the “bun_environment.js” main payload. “This means that the PostHog project has compromised versions in both the JavaScript/npm and Java/Maven ecosystems, driven by the same Shai Hulud v2 payload,” the cybersecurity firm said in an update on Tuesday.

It is worth noting that the Maven Central package is not published by PostHog itself. Instead, the “org.mvnpm” coordinates are generated by an automated mvnpm process that recreates npm packages as Maven objects. The Maven Central team is working on implementing additional protections to prevent the recreation of already known compromised npm components. As of November 25, 2025, all mirrors have been deleted.

This development comes as the “second wave” of the supply chain incident has targeted developers worldwide with the aim of stealing sensitive data such as API keys, cloud credentials, and npm and GitHub tokens, facilitating a deeper breach of the supply chain in a worm-like manner. The latest version has also evolved to be more stealthy, aggressive, scalable, and destructive. In addition to borrowing the overall infection chain of the original September variant, the attack allows malicious actors to gain unauthorized access to npm maintainer accounts and publish modified versions of their packages.

See also: The npm registry worm is still out of control

Shai-Hulud v2 campaign expands from npm to Maven

When unsuspecting developers download and run these libraries, the embedded malicious code creates a backdoor on their own computers, scans for secrets, and exports them to GitHub repositories using the stolen tokens. The attack achieves this by injecting two malicious workflows, one of which registers the victim's machine as a self-hosted cursor and allows arbitrary command execution whenever a GitHub Discussion is opened.

A second workflow is designed to systematically collect all secrets. Over 28,000 repositories have been affected by the incident. “ This release significantly enhances secrecy by using the Bun runtime to hide its underlying logic and increases the potential for scale by increasing the contamination threshold from 20 to 100 packages, ” said Cycode’s Ronen Slavin and Roni Kuznicki

The attacks demonstrate how easy it is for attackers to exploit trusted software distribution channels to push malicious releases at scale and compromise thousands of downstream developers. The self-replicating nature of the malware means that a single compromised account is enough to amplify the blast radius of the attack and turn it into a widespread spread in a short period of time. Further analysis by Aikido revealed that the malicious actors exploited vulnerabilities, specifically focusing on incorrect CI settings in the pull_request_target and workflow_run, in existing GitHub Actions workflows to carry out the attack, and to compromise projects connected to AsyncAPI, PostHog , and Postman.

See also: Over 46,000 fake npm packages flood the Registry

Shai-Hulud v2 campaign expands from npm to Maven

The vulnerability “used the dangerous pull_request_target trigger in a way that allowed code provided by any new pull request during CI execution to be executed,” security researcher Ilyas Makari. “A single misconfiguration can turn a repository into patient zero for a rapidly spreading attack, giving an adversary the ability to push malicious code through automated pipelines you rely on every day.” The activity is believed to be a continuation of a broader set of attacks targeting the ecosystem that began with the S1ngularity in August 2025, affecting several Nx packages on npm.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS