The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
TeamPCP conducted a multi-ecosystem supply chain compromise targeting the @antv package and associated development infrastructure. The attack leveraged GitHub, NPM, and VSCode to steal credentials and establish persistence mechanisms.
- Disclosed
- Last updated
- Blast radius
- Multi-ecosystem; affects GitHub, NPM, and VSCode users; credential theft and persistence mechanisms enable lateral movement.
- Attack vectors
- Threat actor
- Affected entities
- @antvTargeted by TeamPCP in supply chain compromise
TeamPCP has been identified as the actor behind a multi-ecosystem supply chain compromise targeting @antv. The attack exploited multiple platforms including GitHub, NPM, and VSCode to establish a foothold in developer environments.
The threat actor employed credential theft and persistence techniques to enable ongoing access and lateral movement. The compromise affects both the package distribution channel (NPM) and developer tooling (VSCode), indicating a sophisticated approach to supply chain infiltration.
This represents an active threat leveraging account compromise or package manipulation to distribute malicious code across multiple connected ecosystems. Organizations using @antv should audit their environments for unauthorized access and review package integrity.
Remediation
- Immediately audit and revoke any credentials exposed through GitHub or VSCode integrations
- Review @antv package versions and their installation sources; verify package integrity and provenance
- Scan development environments for persistence mechanisms or suspicious artifacts
- Monitor GitHub and NPM accounts for unauthorized activity or commits
- Implement Code Signing verification for package installations
- Isolate affected systems and conduct forensic analysis to identify lateral movement
- Apply principle of least privilege to GitHub tokens and NPM credentials
Sources
Cite this entry
"The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 19, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/the-worm-that-keeps-on-digging-teampcp-hits-antv-in-latest-wave-1lm5r0
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.
ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover - containedcritical
Malicious code in @antv/l7-mapkit (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/l7-mapkit, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-assets-tugraph (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-assets-tugraph was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - activecritical
Malicious code in @antv/gi-assets-hugegraph (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-hugegraph. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit