logo

Massive npm Supply Chain Attack Hits AntV Ecosystem; Hundreds of JavaScript Packages Compromised

ID: 434602ac-0aa2-5bbe-aa58-d6b8cf105ab0

STIX ID: report--434602ac-0aa2-5bbe-aa58-d6b8cf105ab0

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-05-19

Date Updated: 2026-07-20

Author: Mihir Bagwe

...
...

A major npm supply-chain compromise tied to the AntV ecosystem and linked to the 'Mini Shai-Hulud' campaign resulted in malicious versions being published for over 300 packages (including widely used libraries) in a short window; payloads reportedly steal AWS/GitHub/npm credentials, SSH keys, Docker/Kubernetes secrets, attempt container escapes, and propagate across developer workflows, prompting urgent guidance to audit dependencies, pin safe versions, rotate exposed credentials, and run installs with --ignore-scripts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.