frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Shai-Hulud Returns: Over 300 NPM Packages Infected

https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24
61•mrdosija•24m ago

Comments

vintagedave•9m ago
Serious question: should someone develop new technologies using Node any more?

A short time ago, I started a frontend in Astro for a SaaS startup I'm building with a friend. Astro is beautiful. But it's build on Node. And every time I update the versions of my dependencies I feel terrified I am bringing something into my server I don't know about.

I just keep reading more and more stories about dangerous npm packages, and get this sense that npm has absolutely no safety at all.

sublinear•5m ago
The list of affected packages are all under namespaces pretty much nobody uses or are subdependencies of junk libraries nobody should be using if they're serious about writing production code.

I'm getting tired of the anti-Node.js narrative that keeps going around as if other package repos aren't the same or worse.

pxc•3m ago
[delayed]
sph•4m ago
It's not "node" or "Javascript" the problem, it's this convenient packaging model.

This is gonna ruffle some feathers, but it's only a matter of time until it'll happen on the Rust ecosystem which loves to depend on a billion subpackages, and it won't be fault of the language itself.

dkdbejwi383•4m ago
Node itself is still fine and you can do a lot these days without needing tons of library. No need for axios when we have fetch, there's a built-in test runner and assertion library.

There are some things that kind of suck (working with time - will be fixed by the Temporal API eventually), but you can get a lot done without needing lots of dependencies.

Gigachad•2m ago
The problem isn't specific to node. NPM is just the most popular repo so the most value for attacks. The same thing could happen on RubyGems, Cargo, or any of the other package managers.
julius-fx•8m ago
The list of affected packages is concerning - indeed.
timgl•7m ago
co-founder of PostHog here. We were a victim of this attack. We had a bunch of packages published a couple of hours ago. The main packages/versions affected were:

- posthog-node 4.18.1, 5.13.3 and 5.11.3

- posthog-js 1.297.3

- posthog-react-native 4.11.1

- posthog-docusaurus 2.0.6

We've rotated keys and passwords, unpublished all affected packages and have pushed new versions, so make sure you're on the latest version of our SDKs.

We're still figuring out how this key got compromised, and we'll follow up with a post-mortem. We'll update status.posthog.com with more updates as well.

spiderfarmer•4m ago
If we don't know how it got compromised, chances are this attack is still spreading?
spiderfarmer•5m ago
Will the list of affected packages expand? How were these specific packages compromised in the first place?
gonepivoting•4m ago
We're monitoring this activity as well and updating the list of affected packages here: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-...

Currently reverse engineering the malicious payload and will share our findings within the next few hours.

westoque•3m ago
a concern i have is that it's only a matter of time before a similar attack is done to electron based apps (which also have packages installed using npm). probably worse because it's installed in your computer and can potentially get any information especially given admin privileges.
vintagedave•2m ago
The list of packages looks like these are not just tiny solo-person dependencies-of-dependencies. I see AsyncAPI and Zapier there. This is terrifying.

AsyncAPI is used as the example in the post. It says the Github repo was not affected, but NPM was.

What I don't understand from the article is how this happened. Were the credentials for each project leaked? Given the wide range of packages, was it a hack on npm? Or...?

I_am_tiberius•2m ago
I guess you should never use the latest versions of libraries.
rvz•2m ago
Very concerning, so that was what the "impending disaster" was as I first noted. [0] Quite worrying that this happened again to the NPM ecosystem.

Really looking forward to a deeper post-mortem on this.

[0] https://news.ycombinator.com/item?id=46031864

Bill Gates Foundation's 65% Microsoft Stock: Liquidity Play or a Cautious Signal

https://thinkmintmedia.blogspot.com/2025/11/87-billion-question-is-gates.html
1•iamtech•1m ago•0 comments

I put a real search engine into a Lambda, so you only pay when you search

https://nixiesearch.substack.com/p/i-put-a-real-search-engine-into-a
1•shutty•2m ago•0 comments

Thoughtleaderz by Jeff Czekaj

https://czekaj.com/thoughtleaderz.php
1•mankins•6m ago•0 comments

It's Called a Team for a Reason

https://www.codecabin.dev/post/its-called-a-team-for-a-reason
1•rebelchrisycom•6m ago•1 comments

Bookmarklet

https://blog.cloudflare.com/welcome-to-connectivity-cloud/
1•nyeinlay•7m ago•0 comments

No Backup, No Cry

https://world.hey.com/dhh/no-backup-no-cry-274e0c31
1•unripe_syntax•9m ago•0 comments

Show HN: Python UI-ME – Bringing life to Python functions

http://github.com/livetheoogway/python-uime
2•tusharnaik•11m ago•0 comments

OS Malevich – how we made a system that embodies the idea of simplicity (2017)

https://www.ajax-systems.uz/blog/hub-os-malevich-story/
1•frxx•12m ago•0 comments

Music may soothe cats, dogs and other pets

https://www.bbc.com/future/article/20251121-does-music-make-animals-calmer
1•1659447091•13m ago•0 comments

Show HN: Textpilot – Stop copy-pasting into ChatGPT

https://text-pilot.com
2•rawraul•16m ago•0 comments

Bob, Stephen and Marshall Are Leaving the Array Cast

https://www.arraycast.com/episodes/episode118-changes
1•Schiphol•20m ago•0 comments

New Dan Carlin – Common Sense

https://www.dancarlin.com/product/common-sense-325-whos-the-boss/
2•pomian•20m ago•0 comments

Shai-Hulud Returns: Over 300 NPM Packages Infected

https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24
66•mrdosija•24m ago•19 comments

Coderive: A mobile-built programming language without and& and –| operators

https://github.com/DanexCodr/Coderive
1•DanexCodr•24m ago•0 comments

Universal LLM Memory Does Not Exist

https://fastpaca.com/blog/memory-isnt-one-thing
3•cpluss•26m ago•1 comments

I Stopped Using Sublime Text

https://medium.com/@brevis08/why-i-stopped-using-sublime-text-221584ef041f
4•dsego•27m ago•2 comments

General principles for the use of AI at CERN

https://home.web.cern.ch/news/official-news/knowledge-sharing/general-principles-use-ai-cern
2•singiamtel•27m ago•1 comments

Show HN: Open-source tool to list sensitive, unauth & outdated APIs from code

https://github.com/qodex-ai/apimesh
1•siddhant_mohan•29m ago•1 comments

Udo Kier

https://de.wikipedia.org/wiki/Udo_Kier
2•tosh•30m ago•1 comments

Mapping Bob Dylan's Mind

https://aeon.co/essays/can-ai-tell-us-anything-meaningful-about-bob-dylans-songs
1•the-mitr•32m ago•0 comments

Taskforce calls for reset of nuclear regulation in UK

https://www.gov.uk/government/news/taskforce-calls-for-radical-reset-of-nuclear-regulation-in-uk
1•bensouthwood•34m ago•0 comments

Hunter syndrome: Boy amazes doctors after world-first gene therapy

https://www.bbc.co.uk/news/articles/c5y0y56x6veo
3•lkramer•41m ago•0 comments

AltSendme: Another Alternative to MAgic Wormhole?

https://github.com/tonyantony300/alt-sendme
1•nhatcher•47m ago•0 comments

Typing an AI prompt is not 'active' music creation

https://www.theverge.com/report/825141/sunos-ceo-ai-text-prompt-really-active-music-creation
6•JeanKage•51m ago•1 comments

The future LED light both illuminates and communicates

https://www.6gflagship.com/news/future-led-light-illuminates-and-communicates/
1•JeanKage•54m ago•0 comments

Show HN: Deploy a Production Webhook Delivery System in 5 Minutes

https://codehooks.io/blog/build-webhook-delivery-system-5-minutes-codehooks-io
3•bjabrboe1984•54m ago•0 comments

A Tsunami of Cogs

https://betterthanrandom.substack.com/p/a-tsunami-of-cogs
3•weltview•54m ago•0 comments

I've built human-first alternative to 11x

https://dealmayker.com/alternative/11x
1•aleksam•55m ago•0 comments

ASML allegedly offered to spy on China for the US

https://www.tomshardware.com/tech-industry/big-tech/asml-allegedly-offered-to-spy-on-china-for-th...
5•dataflow•56m ago•0 comments

Pig's bacon was delicious. But she's alive and well

https://grist.org/climate-energy/this-pigs-bacon-was-delicious-but-shes-alive-and-well/
4•JeanKage•58m ago•1 comments