Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
ID: 2791213f-c7f9-5f5c-99fb-ce1e7eec22d3
STIX ID: report--2791213f-c7f9-5f5c-99fb-ce1e7eec22d3
Feed Name: The Hacker News
Security researchers have identified a large, active software supply-chain campaign (Mini Shai-Hulud) that compromised an npm maintainer account tied to the @antv ecosystem, publishing 639 malicious package versions across 323 packages. The payload is a credential stealer that harvests over 20 credential types, exfiltrates data to t.m-kosche.com:443 and via GitHub repo commits, abuses stolen npm/GitHub tokens to propagate by republishing trojanized packages, and leverages Sigstore/OIDC provenance forgery to make malicious releases appear legitimate; the campaign is attributed to TeamPCP and has been open-sourced, enabling copycat activity and wide downstream exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
