Shai-Hulud Returns: Massive npm Supply Chain Attack Hijacks AntV Ecosystem to Scrape GitHub Runner Memory
ID: 02ee6a01-0e6d-54cf-98b2-caf35d700b84
STIX ID: report--02ee6a01-0e6d-54cf-98b2-caf35d700b84
Feed Name: securityonline.info
StepSecurity reports a massive, coordinated npm supply-chain campaign on May 19, 2026 that hijacked the atool publisher (including timeago.js and AntV packages) to distribute a heavily obfuscated JavaScript worm. The worm uses a two-wave publish strategy and multiple injection patterns to run a payload that hunts GitHub Actions runner memory for secrets, harvests credentials across cloud and developer tooling, escalates privileges, persists in developer workflows, and exfiltrates data via commits to a legitimate repository or a TLS C2, with evidence of thousands of automated malicious repositories being created.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
