216.73.216.6

Active Supply Chain Attack Compromises Packages on npm

· Published 19/05/2026 10:11 · Modified 19/05/2026 17:59

Export JSON

Essential information

Published
19/05/2026 10:11
Modified
19/05/2026 17:59
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
@antv packages ci/cd compromise credential theft echarts-for-react github exfiltration mini shai-hulud npm supply chain attack
Tags
2026-05-19 @antv packages ci/cd compromise credential-theft echarts-for-react github exfiltration mini shai hulud npm supply chain attack
Related entities
2 indicators, 2 observables, 17 techniques (mitre), 1 malware, 2 others

Description

An active has compromised packages in the @antv ecosystem, affecting the maintainer account 'atool'. The attack is part of the campaign, involving 639 compromised package versions across 323 unique packages. Notable affected packages include with 1.1 million weekly downloads, and widely-used @antv packages for data visualization. The malware uses obfuscated install-time payloads that harvest developer credentials, GitHub tokens, tokens, AWS credentials, and other secrets from development and CI/CD environments. Stolen data is encrypted with AES-256-GCM and exfiltrated to a command-and-control server, with GitHub repositories used as fallback channels. The malware contains worm-like functionality to republish compromised packages and propagate through the ecosystem.

External references