Post-mortem of Shai-Hulud attack on November 24th, 2025
21–30 of 77 posts
Re: Post-mortem of Shai-Hulud attack on November 24th, 2025
#22Posthog's website design feels like a joke that went a bit too far
Other than the silly design, the website's cookie banner is actively malicious. It proclaims to be legally required and directly blames the President of the European Commission. If Posthog is being truthful about its cookie usage, the cookie banner is in fact not legally required. Consent banners are only required if you're trying to do individual user tracking or collecting personally identifying data; technical coo…
Re: Post-mortem of Shai-Hulud attack on November 24th, 2025
#23I didn’t know what Posthog was before this event but the website is so unusable on Safari on MacOS or iOS for me i’m surprised I stuck through to discover the product.
Re: Post-mortem of Shai-Hulud attack on November 24th, 2025
#24So it wasn't phishing attack? Wonder how those bot access tokens got stolen.
> The PR was opened, the workflow run, and the PR closed within the space of 1 minute (screenshots include timestamps in UTC+2, the author's timezone): It's an unfortunately common problem with GitHub Actions, it's easy to set things up to where any PR that's opened against your repo runs the workflows as defined in the branch. So you fork, make a malicious change to an existing workflow, and open a PR, and your code…
I think the mistake was to put secrets in there and allow publishing directly from github's CI.
Hilariously the people at pypi advise to use trusted publishers (publishing on pypi from github rather than local upload) as a way to avoid this issue.
Re: Post-mortem of Shai-Hulud attack on November 24th, 2025
#25Posthog's website design feels like a joke that went a bit too far
Re: Post-mortem of Shai-Hulud attack on November 24th, 2025
#26I didn’t know what Posthog was before this event but the website is so unusable on Safari on MacOS or iOS for me i’m surprised I stuck through to discover the product.
Re: Post-mortem of Shai-Hulud attack on November 24th, 2025
#27Long story short: they messed up the assign-reviewers.yml workflow, allowing external contributors to merge PRs without proper reviews. From this point on, you're fully open to all kinds of bad stuff.
Re: Post-mortem of Shai-Hulud attack on November 24th, 2025
#28Re: Post-mortem of Shai-Hulud attack on November 24th, 2025
#29Posthog's website design feels like a joke that went a bit too far
Other than the silly design, the website's cookie banner is actively malicious. It proclaims to be legally required and directly blames the President of the European Commission. If Posthog is being truthful about its cookie usage, the cookie banner is in fact not legally required. Consent banners are only required if you're trying to do individual user tracking or collecting personally identifying data; technical coo…
Re: Post-mortem of Shai-Hulud attack on November 24th, 2025
#30I didn’t know what Posthog was before this event but the website is so unusable on Safari on MacOS or iOS for me i’m surprised I stuck through to discover the product.
Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting. https://news.ycombinator.com/newsguidelines.html