Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

Malicious code in @antstackio/json-to-graphql (npm)

The npm package @antstackio/json-to-graphql was compromised and contained malicious code as part of the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other npm packages owned by the user, and may destroy the user's home directory.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users who installed @antstackio/json-to-graphql; secondary propagation to other npm packages owned by affected users.
Ecosystems
Attack vectors
Threat actor
Affected entities
  • @antstackio/json-to-graphql

The npm package @antstackio/json-to-graphql was found to contain malicious code, identified by both Amazon Inspector and Google Open Source Security scanning tools. The compromise was attributed to the Sha1-Hulud: The Second Coming NPM worm.\n\nThe malicious payload performs multiple harmful actions: it steals authentication tokens and credentials, publishes them to GitHub, and attempts to establish persistence by modifying GitHub Actions. The worm is designed to self-propagate to other npm packages owned by the compromised user.\n\nAdditionally, the malicious code may destroy the user's home directory, representing a severe threat to system integrity. The incident was documented by the OpenSSF malicious packages repository.\n\nThis represents a supply chain compromise affecting all users who installed the affected package version(s).

Indicators of compromise

Packages
  • @antstackio/json-to-graphql

Remediation

  • Immediately remove @antstackio/json-to-graphql from all projects and dependencies
  • Rotate all npm authentication tokens and GitHub credentials
  • Audit GitHub Actions workflows for unauthorized modifications or persistence mechanisms
  • Review GitHub commit history and published packages for unauthorized changes
  • Scan systems for signs of home directory destruction or data loss
  • Check for propagation of the worm to other npm packages owned by the user
  • Monitor npm account activity for unauthorized package publications
  • Consider full security audit of development environment and CI/CD pipelines

Sources

  1. GitHub Advisory GHSA-2m9w-297v-v4x6 · GitHub Advisory Database

Cite this entry

"Malicious code in @antstackio/json-to-graphql (npm)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 26, 2026; last updated July 26, 2026. https://supplychainattack.org/incident/malicious-code-in-antstackio-json-to-graphql-npm-sxufdi

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/f-wx (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/f-wx. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g-web-components (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages in a 22-minute automated burst, including @antv/g-web-components. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in @antv/dipper-hooks (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/dipper-hooks, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials (AWS keys, GitHub PATs, npm tokens, GCP service accounts, Azure credentials, Kubernetes tokens, SSH keys, Docker configs, database strings, Stripe keys, Slack tokens) via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antstackio/shelbysam (npm)

    The npm package @antstackio/shelbysam was compromised and contained malicious code associated with the Sha1-Hulud: The Second Coming NPM worm. The malicious payload steals tokens and credentials, publishes them to GitHub, propagates to other NPM packages owned by the user, and may destroy the user's home directory.

    Shai-HuludnpmCompromised packageMalicious commit