postman-shai-hulud-2025 · Disclosed 2025-11-24
Postman: poisoned dependencies exposed CI publishing authority
A CI build without an appropriate lockfile installed infected dependencies, enabling misuse of an npm publishing token. Postman reported 17 hijacked packages, with production apps and customer data unaffected.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
GitHub Actions installed infected AsyncAPI packages; a publishing token could publish to 17 packages lacking the disallow-tokens/two-factor setting.
[s1]How did it happen? - Reported fact
Infected versions of 17 public npm packages were distributed; Postman attributes production and customer-data isolation to segmented environments.
[s1]What happened?
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Postman revoked the account’s tokens, removed infected versions, restricted publishing access, enabled OIDC Trusted Publishers, and began checking lockfiles.
[s1]How did it happen? / What we have already done
Evidence relevant to prevention
Operational controls to inspect
Inspect lockfiles, frozen installs, CI publishing authority, and long-lived tokens; lockfiles alone do not establish dependency safety.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
This record covers Postman packages rather than the whole campaign. Source timestamps use PT; an initial-entry UTC date is not assigned here.
Sources
[s1] Postman · Primary source
Root Cause Analysis: Shai-Hulud 2.0 ↗Published 2025-12-04 · Reviewed 2026-10-02