Post-mortem of Shai-Hulud attack on November 24th, 2025
Blog post from PostHog
In a recent security incident, PostHog's JavaScript SDKs were compromised by the Shai-Hulud 2.0 worm, which exploited a vulnerability in their workflow automation to publish malicious packages on npm. The attack involved stealing a GitHub Personal Access Token from one of PostHog's bots, which allowed the attacker to exfiltrate sensitive credentials and propagate the breach. PostHog quickly responded by identifying and deleting the malicious packages, revoking tokens, and rolling potentially compromised credentials. The attack highlighted a misunderstanding in PostHog's use of GitHub's workflow triggers, allowing a pull request to execute arbitrary code and steal credentials. In response, PostHog has enhanced its security measures, including tightening package release workflows, increasing scrutiny on workflow modifications, and improving GitHub secrets management. This incident has prompted PostHog to prioritize broad security measures and seek talent to strengthen their security team.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 7 | 1,471 | 226 | 98 | +14% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.