Malware in PostHog NPM packages
roskoalexey Monday, November 24, 2025I know many of us use a really excellent PostHog service, but it seems their latest version of `posthog-js` NPM package contains malware.
Reported to their security channel, also reported to NPM, but also wanted to raise awareness here.
Update: It seems all their NPM packages have the same problem
Update 2: https://status.posthog.com/
10
7