Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
ID: 021d48ea-1899-57de-a3b0-9eb4e25123ff
STIX ID: report--021d48ea-1899-57de-a3b0-9eb4e25123ff
Feed Name: Microsoft Security
Date Published: 2026-05-20
Date Updated: 2026-05-20
Author: Microsoft Defender Security Research Team
*Executive summary:* Microsoft details an active npm supply-chain compromise of the @antv account where attacker-published malicious package versions executed an obfuscated payload during installation to steal credentials from GitHub Actions, AWS, HashiCorp Vault, npm, Kubernetes, and 1Password, perform runner memory scraping, escalate privileges, and exfiltrate data via encrypted C2 and the Git Data API; GitHub removed malicious packages and invalidated tens of thousands of tokens while Microsoft provides detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
