Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem

A new wave of the Mini Shai-Hulud worm has compromised multiple npm packages across Alibaba's AntV data visualization ecosystem, including echarts-for-react and timeago.js. Stolen CI/CD secrets are being exfiltrated and dumped to thousands of public GitHub repositories as the attack spreads.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Thousands of public GitHub repositories affected; multiple packages across Alibaba's AntV ecosystem and dependent projects compromised
Ecosystems
Attack vectors
Threat actor
Affected entities
  • echarts-for-reactAntV ecosystem package
  • timeago.jsAntV ecosystem package
  • AntV ecosystem packagesMultiple packages across Alibaba's data visualization ecosystem

A renewed campaign of the Mini Shai-Hulud worm has targeted and compromised packages within Alibaba's AntV ecosystem—a widely-used data visualization library. Confirmed affected packages include echarts-for-react and timeago.js, among dozens of others across the ecosystem.

The attack exploits compromised npm accounts or packages to inject malicious code. Once executed, the worm harvests CI/CD secrets from affected development environments and exfiltrates them to attacker-controlled infrastructure.

Stolen credentials are being systematically dumped to thousands of public GitHub repositories, amplifying the blast radius and enabling downstream attacks against dependent projects and organizations that use these libraries.

The attack remains active and ongoing as of the publication date, with continued exploitation and credential exfiltration observed.

Remediation

  • Review the linked advisory; remove or upgrade the affected component and rotate any exposed credentials.

Sources

  1. Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem · StepSecurity

Cite this entry

"Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 19, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/shai-hulud-here-we-go-again-mass-npm-supply-chain-attack-hits-the-antv-ecosystem-1kfeld

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in jest-canvas-mock (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including jest-canvas-mock, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in mcp-mermaid (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including mcp-mermaid, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in @antv/li-editor (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/gi-mock-data (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-mock-data, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit