Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Adobe Commerce Flaws Let Attackers Execute Code (CVE-2024-20724, CVE-2024-20725)
August 13, 2026
Cisco ASA, FTD Critical 0-Day Lets Attackers Trigger DoS
August 13, 2026
Critical WordPress Imagick RCE (CVE-2022-XXXX) Lets Authors Execute Code
August 13, 2026
Home/Threats/Critical Vulnerabilities Found in @antv Packages After npm Attack
Threats

Critical Vulnerabilities Found in @antv Packages After npm Attack

Key Takeaways A significant supply chain attack, dubbed “Mini Shai-Hulud,” compromised hundreds of npm JavaScript packages, including those related to the @antv data visualization...

Sarah simpson
Sarah simpson
May 19, 2026 4 Min Read
68 0

Key Takeaways

  • A significant supply chain attack, dubbed “Mini Shai-Hulud,” compromised hundreds of npm JavaScript packages, including those related to the @antv data visualization library.
  • The attackers leveraged a compromised npm maintainer account (“atool”) to inject malicious code into 639 package versions across 323 unique packages, impacting millions of developers.
  • The malware, active since May 19, 2026, is designed to steal sensitive credentials (e.g., GitHub tokens, AWS keys, Kubernetes secrets) from developer and CI/CD environments.
  • A unique exfiltration method involves creating new GitHub repositories under victim accounts, making detection challenging. The malware also exhibits worm-like behavior to spread further.
  • Immediate action is required from developers and organizations to audit dependencies, rotate compromised credentials, and monitor for suspicious GitHub activity.

Widespread Supply Chain Attack Targets npm Ecosystem, Compromising @antv Packages

In a far-reaching supply chain incident, malicious actors have infiltrated hundreds of popular JavaScript packages within the npm ecosystem, with a particular focus on those associated with the @antv data visualization library. The attack, which began on May 19, 2026, injected harmful code into packages utilized by millions of developers globally.

Table Of Content

  • Key Takeaways
  • Widespread Supply Chain Attack Targets npm Ecosystem, Compromising @antv Packages
  • Real-Time Detection and Campaign Scope
  • Malicious Payload and Exfiltration Techniques
  • GitHub as a Covert Exfiltration Channel
  • What You Should Do
  • Indicators of Compromise (IoCs)

Among the high-profile targets was echarts-for-react, a React wrapper with approximately 1.1 million weekly downloads. Threat actors compromised the npm maintainer account “atool” to push malicious versions of numerous well-known packages. The attack extended beyond core @antv packages to include unrelated projects such as timeago.js, size-sensor, and canvas-nest.js, making it one of the most extensive npm supply chain incidents in recent memory.

Real-Time Detection and Campaign Scope

Security researchers at Socket.dev identified the attack in near real-time, categorizing affected versions as known malware. Their internal analysis revealed 639 compromised package versions across 323 unique packages, which they termed the “5/19 Mini Shai-Hulud wave.” Most of these detections occurred within 6 to 12 minutes of publication.

The broader “Mini Shai-Hulud” campaign has tracked 1,055 versions across 502 unique packages spanning npm, PyPI, and Composer registries. The npm ecosystem accounts for the vast majority, with 1,048 compromised versions across 498 unique npm packages. This scale suggests a highly coordinated and well-resourced threat actor operating across multiple open-source platforms.

The impact is substantial, as the compromised publishing account is linked to packages crucial for data visualization, graphing, mapping, and React component development. Organizations that automatically fetch new dependency versions are at considerable risk of downstream exposure, even if only a fraction of these packages received a malicious update.

Malicious Payload and Exfiltration Techniques

The injected code aligns with the Mini Shai-Hulud malware family. Each compromised package contains a root-level index.js file designed to modify package.json. This modification incorporates a “preinstall” hook that executes the payload via Bun during installation. The payload itself is heavily obfuscated, employing an extensive string-array lookup table and a custom decryptor to conceal sensitive strings from basic analysis.

Upon execution, the malware collects and transmits stolen data through an encrypted channel. It serializes the harvested information, compresses it with gzip, encrypts it using AES-256-GCM, and then wraps the encryption key with RSA-OAEP before dispatching it to a command-and-control (C2) server. This multi-layered encryption significantly hinders defenders’ ability to recover stolen data from network traffic logs.

The payload actively seeks high-value secrets within developer and CI/CD environments. It specifically targets GitHub tokens, AWS credentials, Kubernetes service-account details, SSH private keys, Vault tokens, Docker authentication files, and database connection strings. Furthermore, it includes platform-specific logic tailored for environments like GitHub Actions, GitLab CI, Jenkins, CircleCI, and AWS CodeBuild, among others.

GitHub as a Covert Exfiltration Channel

If the malware successfully obtains a usable GitHub token, it switches to a secondary, more stealthy exfiltration method. It creates a new repository under the victim’s GitHub account and commits the stolen data into files following a structured naming convention. This technique exploits GitHub’s trusted infrastructure, making the exfiltration process much harder to detect and block.

Public GitHub searches for a specific reversed campaign marker currently reveal approximately 1,900 repositories created by the threat actor. These repositories use “Dune”-inspired names like “sayyadina-stillsuit-852” and “fremen-fedaykin-225,” and their descriptions contain the same reversed marker, confirming their association with the campaign’s exfiltration network.

Beyond data theft, the payload also possesses self-propagation capabilities. It validates stolen npm credentials, identifies packages the compromised account can publish, injects its malicious code, and then republishes the altered packages. This worm-like behavior allows the attack to spread autonomously across maintainer accounts without further direct intervention from the attackers.

What You Should Do

  • Audit Dependencies: Immediately review all recent updates from @antv and associated npm namespaces. Identify any compromised package versions and roll back to safe versions.
  • Rotate Credentials: Assume compromise for any secrets or credentials (GitHub tokens, AWS keys, SSH keys, Vault tokens, etc.) that may have been present in environments where these malicious packages were installed. Rotate all affected credentials without delay.
  • Monitor CI/CD Pipelines: Scrutinize CI/CD pipeline logs for any anomalous activity, particularly unexpected GitHub repository creation or unusual outbound network connections.
  • Implement Strict Access Controls: Enforce the principle of least privilege for npm accounts and other development tooling. Consider multi-factor authentication (MFA) for all critical accounts.
  • Enhance Supply Chain Security: Utilize security tools that can analyze package dependencies for known vulnerabilities and suspicious behavior during installation.

Indicators of Compromise (IoCs)

Type Indicator Description
Domain t[.]m-kosche[.]com Primary C2 exfiltration domain used by the malicious payload
URL https://t[.]m-kosche[.]com:443/api/public/otel/v1/traces Primary HTTPS exfiltration endpoint for harvested secrets <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/41463a42-244a-4713-ac22-9d12fcd7470e/Hackers-Compromise-antv-Packages-in-Mini-Shai-Hulud-npm-Attack-Wave.pdf?AWSAccessKeyId=ASIA2F3EMEYEWYS2HVOA&Signature=rUISmJQwC2uedp4tw8OtvJ54hZc%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEAkaCXVzLWVhc3QtMSJHMEUCIQDh1gbtxykDub1SpoErt6PODN%2F2jFKasGRA23WfOTnlJwIgGZwY9rx74uN1dN73ZCM%2F0UobbUeRbmAqpJrkaWwh9Ogq%2FAQI0f%2F%2F

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

CISA Administrator Exposed AWS GovCloud Credentials on Public GitHub

Next Post

Critical SEPPmail Vulnerabilities Allow RCE, Data Theft

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
China-linked Hackers Use AI Agents to Attack Taiwan Government Websites
August 12, 2026
Critical Adobe ColdFusion flaws let attackers run arbitrary code
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us