logo

Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines

ID: d8caef40-55c4-5689-bb11-f467252bf6ef

STIX ID: report--d8caef40-55c4-5689-bb11-f467252bf6ef

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

Microsoft and other security teams observed a fast-moving supply-chain campaign (called Mini Shai-Hulud) that compromised an @antv npm maintainer account to publish hundreds of malicious package variants. The injected ~499 KB obfuscated JavaScript executes during installs and in CI/CD runners, performing multi-platform credential theft (GitHub, AWS, Vault, npm, Kubernetes, 1Password), memory scraping of GitHub Action runners, privilege escalation, SLSA provenance forgery, and dual-channel exfiltration using stolen keys and automated Git repos; remediation actions removed packages and invalidated tens of thousands of tokens but the threat remains high due to rapid automated propagation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.