Threat actors published 600+ malicious versions to npm as part of the Shai-Hulud supply chain campaign; most of the affected packages are in the @antv ecosystem
Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign.
BleepingComputerBill Toulas
Context & Ripple Effects
Related coverage shows a run of npm supply-chain compromises in 2026, beginning with a malicious dependency in selected Axios releases and later affecting packages associated with SAP, Intercom, Mistral, UiPath, and TanStack tools. The activity has been described in prior coverage as Mini Shai-Hulud.
This report marks a substantial expansion in package count and a concentration in the @antv ecosystem, shifting the issue from isolated high-profile package compromises to a broader registry-cleanup and dependency-review problem.
First-order effects
Developers and organizations using affected @antv packages must identify whether they installed one of the malicious versions and replace or remove it; npm consumers face an immediate version-selection risk while those releases remain available.
Maintainers and owners in the affected ecosystem face urgent incident-response work: validating published versions, revoking compromised access where applicable, and communicating safe releases to downstream users.
Second-order effects
Teams that depend on @antv transitively will need to audit lockfiles and build artifacts, not just direct dependencies, increasing remediation work for application and tooling vendors.
The breadth of the publication campaign raises pressure on npm package consumers to tighten dependency-update controls and on adjacent registries and maintainers to review account and release protections, following earlier npm and PyPI incidents.
Third-order effects
If repeated campaigns continue to move from individual popular packages to large coordinated publication waves, open-source dependency consumption will increasingly require provenance checks and constrained update policies as standard engineering practice.
The pattern could further concentrate trust in registries, maintainers, and security tooling that can verify releases quickly; the available coverage does not establish which defensive model will prove most effective.
The trend: This is another data point in the shift from one-off open-source package compromises toward recurring, ecosystem-scale software-supply-chain attacks that exploit the distribution reach of public registries.
Microsoft is investigating a new, emerging Mini Shai-Hulud npm supply chain attack targeting antv packages. Attackers compromised an antv maintainer account and published malicious versions of multiple widely used packages (for example, antv/g2). As these packages are widely [ima…
Mini Shai Hulud strikes again... again! We've identified three malicious versions of Microsoft's durabletask on PyPI, 1.4.1, 1.4.2, and 1.4.3, that contain a dropper injected directly into the package's Python source files. This does smell of more TeamPCP shenanigans, but we
NPM is owned by GitHub which is owned by Microsoft. So this is basically lost battle. Someone like @vercel or @Cloudflare should push their own solution for NPM packages. They have the infra, skills and good idea how “secure” NPM should look like. Current state of NPM is that
“Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised” I think I'm going to drop NPM from my host and just shove everything into VMs. This ain't getting better any time soon.
🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @antv ecosystem. The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool. [image]
“Shai Hulud: Here We Go Again” (May 19 wave) PyPI supply chain campaign has returned! “durabletask” versions 1.4.1, 1.4.2, 1.4.3 have been compromised. These versions have been uploaded to PyPI ~2 hours ago and are STILL LIVE 🧵
🚨 Shai-Hulud is back. Compromising major packages like Alibaba's @antv suite, echarts-for-react, and timeago.js. Scrapes secrets from CI/CD runners, steals cloud and SSH credentials, plants backdoors in VS Code and Claude Code. 2,700+ GitHub repos spun up using stolen tokens.
We published our technical analysis. The @ antv payload includes worm-like npm propagation logic: validate stolen npm tokens, enumerate packages, inject the payload, bump versions, and republish under the compromised maintainer identity. This is why these attacks can move so