Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages
ID: 74e560da-31c3-543d-b8fa-f45ff29d3833
STIX ID: report--74e560da-31c3-543d-b8fa-f45ff29d3833
Feed Name: Aikido Security's Blog
Mini Shai-Hulud is an active npm supply-chain campaign that injected obfuscated install-time JavaScript (root-level index.js and exotic GitHub deps) into hundreds of packages—including @antv, echarts-for-react, and timeago.js—to harvest CI/developer secrets (tokens, SSH keys, cloud creds), exfiltrate them (including committing to attacker-created GitHub repos), propagate by republishing compromised packages with stolen npm tokens, and persist via modifications to .vscode/tasks.json and .claude/settings.json; over 2,700 rogue GitHub repositories have been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
