Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave

TeamPCP conducted a multi-ecosystem supply chain compromise targeting the @antv package and associated development infrastructure. The attack leveraged GitHub, NPM, and VSCode to steal credentials and establish persistence mechanisms.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Multi-ecosystem; affects GitHub, NPM, and VSCode users; credential theft and persistence mechanisms enable lateral movement.
Ecosystems
Attack vectors
Threat actor
Affected entities
  • @antvTargeted by TeamPCP in supply chain compromise

TeamPCP has been identified as the actor behind a multi-ecosystem supply chain compromise targeting @antv. The attack exploited multiple platforms including GitHub, NPM, and VSCode to establish a foothold in developer environments.

The threat actor employed credential theft and persistence techniques to enable ongoing access and lateral movement. The compromise affects both the package distribution channel (NPM) and developer tooling (VSCode), indicating a sophisticated approach to supply chain infiltration.

This represents an active threat leveraging account compromise or package manipulation to distribute malicious code across multiple connected ecosystems. Organizations using @antv should audit their environments for unauthorized access and review package integrity.

Remediation

  • Immediately audit and revoke any credentials exposed through GitHub or VSCode integrations
  • Review @antv package versions and their installation sources; verify package integrity and provenance
  • Scan development environments for persistence mechanisms or suspicious artifacts
  • Monitor GitHub and NPM accounts for unauthorized activity or commits
  • Implement Code Signing verification for package installations
  • Isolate affected systems and conduct forensic analysis to identify lateral movement
  • Apply principle of least privilege to GitHub tokens and NPM credentials

Sources

  1. The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave · Wiz

Cite this entry

"The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 19, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/the-worm-that-keeps-on-digging-teampcp-hits-antv-in-latest-wave-1lm5r0

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/gi-assets-basic (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in gantt-for-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/gi-sdk-app (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit