logo

Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages

ID: 74e560da-31c3-543d-b8fa-f45ff29d3833

STIX ID: report--74e560da-31c3-543d-b8fa-f45ff29d3833

Feed Name: Aikido Security's Blog

Threat Score
90/100

Date Published: 2026-05-19

Date Updated: 2026-07-24

...
...

Mini Shai-Hulud is an active npm supply-chain campaign that injected obfuscated install-time JavaScript (root-level index.js and exotic GitHub deps) into hundreds of packages—including @antv, echarts-for-react, and timeago.js—to harvest CI/developer secrets (tokens, SSH keys, cloud creds), exfiltrate them (including committing to attacker-created GitHub repos), propagate by republishing compromised packages with stolen npm tokens, and persist via modifications to .vscode/tasks.json and .claude/settings.json; over 2,700 rogue GitHub repositories have been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.