Home / Companies / PostHog / Blog / Post Details
Content Deep Dive

Post-mortem of Shai-Hulud attack on November 24th, 2025

Blog post from PostHog

Post Details
Company
Date Published
Author
Oliver Browne
Word Count
1,870
Company Posts That Month
6
Language
-
Hacker News Points
-
Post removed?
No
Summary

In a recent security incident, PostHog's JavaScript SDKs were compromised by the Shai-Hulud 2.0 worm, which exploited a vulnerability in their workflow automation to publish malicious packages on npm. The attack involved stealing a GitHub Personal Access Token from one of PostHog's bots, which allowed the attacker to exfiltrate sensitive credentials and propagate the breach. PostHog quickly responded by identifying and deleting the malicious packages, revoking tokens, and rolling potentially compromised credentials. The attack highlighted a misunderstanding in PostHog's use of GitHub's workflow triggers, allowing a pull request to execute arbitrary code and steal credentials. In response, PostHog has enhanced its security measures, including tightening package release workflows, increasing scrutiny on workflow modifications, and improving GitHub secrets management. This incident has prompted PostHog to prioritize broad security measures and seek talent to strengthen their security team.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 7 1,471 226 98 +14%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.