Hackers Compromise @antv npm Packages In Mini Shai-Hulud Attack Wave
ID: acfbcb13-a9ef-539b-aa6c-5cc8491ee1f2
STIX ID: report--acfbcb13-a9ef-539b-aa6c-5cc8491ee1f2
Feed Name: Cyber Press
Researchers discovered a coordinated supply-chain attack (Mini Shai-Hulud) that compromised a maintainer account to publish hundreds of malicious versions across the @antv/npm ecosystem — including high-download libraries like echarts-for-react. The payload executes via a preinstall Bun hook, uses heavy obfuscation and encryption to steal developer secrets (GitHub, npm, AWS, Kubernetes, database credentials), exfiltrates data to a hardcoded HTTPS domain (t.m-kosche.com) or by creating themed GitHub repositories, and self-propagates by abusing stolen npm tokens to inject and republish poisoned packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
