logo

Mini Shai-Hulud Compromises @antv npm Packages to Steal CI/CD Credentials

ID: 984cc561-21b0-5afe-bbde-b3f826cb8fd2

STIX ID: report--984cc561-21b0-5afe-bbde-b3f826cb8fd2

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Tushar Subhra Dutta

...
...

Mini Shai-Hulud is a sophisticated supply-chain attack that compromised the @antv npm account to publish malicious packages which executed during npm install via preinstall hooks; the obfuscated ~499 KB JavaScript payload targeted GitHub Actions environments and stole credentials across AWS, HashiCorp Vault, Kubernetes, npm, and 1Password, exfiltrating data via encrypted HTTPS to a C2 and by creating GitHub commits. Microsoft researchers reported the campaign, GitHub removed hundreds of malicious packages and invalidated tens of thousands of npm tokens, and IoCs (SHA-256s, domains, filenames) and mitigation steps (ignore-scripts, pinning, credential rotation, audit repos) were provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.