PostHog admits Shai-Hulud 2.0 was its biggest ever security bungle

go.theregister.com/feed/www.theregister.com/2025/11/28/posthog_shaihulud

Automation flaw in CI/CD workflow let a bad pull request unleash worm into npm
PostHog says the Shai-Hulud 2.0 npm worm compromise was "the largest and most impactful security incident" it's ever experienced after attackers slipped malicious releases into its JavaScript SDKs and tried to…

This story appeared on go.theregister.com, 2025-11-28 16:22:08.
The Entire Business World on a Single Page. Free to Use →