Threat actors published 600+ malicious versions to npm as part of the Shai-Hulud supply chain campaign; most of the affected packages are in the @antv ecosystem
Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign.
BleepingComputer Bill Toulas
Related Coverage
- Active Supply Chain Attack Compromises @antv Packages on npm Socket
- Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages Aikido Security's Blog · Sooraj Shah
- AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks InfoWorld · John E. Dunn
- Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account Snyk · Liran Tal
- Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem Step Security Blog · Sai Likhith
- Mini Shai-Hulud Returns: 600+Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack Endor Labs · Peyton Kennedy
Discussion
-
@msftsecintel
@msftsecintel
on x
Microsoft is investigating a new, emerging Mini Shai-Hulud npm supply chain attack targeting antv packages. Attackers compromised an antv maintainer account and published malicious versions of multiple widely used packages (for example, antv/g2). As these packages are widely [ima…
-
@socketsecurity
@socketsecurity
on x
🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @antv ecosystem. The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool. [image]
-
@adnanthekhan
Adnan Khan
on x
This one is really, really bad. https://github.com/... Starting to be hard to call this one “Mini Shai-Hulud”
-
@theo
@theo
on x
Hey, npm? You there? It's time to wake up and do literally anything at all about this
-
@zackkorman
Zack Korman
on x
Might be a dumb question, but how are devs on personal machines supposed to catch this? Or do a lot of them just stay pwned and never know it? [image]
-
@felixiscoding
Guilherme Dos Santos
on x
how installing an npm package feels nowadays [image]
-
@socketsecurity
@socketsecurity
on x
We published our technical analysis. The @ antv payload includes worm-like npm propagation logic: validate stolen npm tokens, enumerate packages, inject the payload, bump versions, and republish under the compromised maintainer identity. This is why these attacks can move so