Ecosystem Poisoned: Mini Shai-Hulud Worm Hijacks @antv npm Packages to Target CI/CD Pipelines
ID: d8caef40-55c4-5689-bb11-f467252bf6ef
STIX ID: report--d8caef40-55c4-5689-bb11-f467252bf6ef
Feed Name: securityonline.info
Microsoft and other security teams observed a fast-moving supply-chain campaign (called Mini Shai-Hulud) that compromised an @antv npm maintainer account to publish hundreds of malicious package variants. The injected ~499 KB obfuscated JavaScript executes during installs and in CI/CD runners, performing multi-platform credential theft (GitHub, AWS, Vault, npm, Kubernetes, 1Password), memory scraping of GitHub Action runners, privilege escalation, SLSA provenance forgery, and dual-channel exfiltration using stolen keys and automated Git repos; remediation actions removed packages and invalidated tens of thousands of tokens but the threat remains high due to rapid automated propagation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
