← Incident database

postman-shai-hulud-2025 · Disclosed 2025-11-24

Postman: poisoned dependencies exposed CI publishing authority

A CI build without an appropriate lockfile installed infected dependencies, enabling misuse of an npm publishing token. Postman reported 17 hijacked packages, with production apps and customer data unaffected.

Supply chain / CICredentialsConfiguration / exposure

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    GitHub Actions installed infected AsyncAPI packages; a publishing token could publish to 17 packages lacking the disallow-tokens/two-factor setting.

    [s1]How did it happen?
  • Reported fact

    Infected versions of 17 public npm packages were distributed; Postman attributes production and customer-data isolation to segmented environments.

    [s1]What happened?

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Postman revoked the account’s tokens, removed infected versions, restricted publishing access, enabled OIDC Trusted Publishers, and began checking lockfiles.

    [s1]How did it happen? / What we have already done

Evidence relevant to prevention

Operational controls to inspect

Inspect lockfiles, frozen installs, CI publishing authority, and long-lived tokens; lockfiles alone do not establish dependency safety.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

This record covers Postman packages rather than the whole campaign. Source timestamps use PT; an initial-entry UTC date is not assigned here.

Sources

  1. [s1] Postman · Primary source

    Root Cause Analysis: Shai-Hulud 2.0 ↗

    Published 2025-12-04 · Reviewed 2026-10-02