logo

Hackers Compromise @antv npm Packages In Mini Shai-Hulud Attack Wave

ID: acfbcb13-a9ef-539b-aa6c-5cc8491ee1f2

STIX ID: report--acfbcb13-a9ef-539b-aa6c-5cc8491ee1f2

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Varshini

...
...

Researchers discovered a coordinated supply-chain attack (Mini Shai-Hulud) that compromised a maintainer account to publish hundreds of malicious versions across the @antv/npm ecosystem — including high-download libraries like echarts-for-react. The payload executes via a preinstall Bun hook, uses heavy obfuscation and encryption to steal developer secrets (GitHub, npm, AWS, Kubernetes, database credentials), exfiltrates data to a hardcoded HTTPS domain (t.m-kosche.com) or by creating themed GitHub repositories, and self-propagates by abusing stolen npm tokens to inject and republish poisoned packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.