[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fatQoIoqZus6SE3cpY1JybmG4muYLR6k7ayst4wEfakE":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"b3d6485f-a670-43d8-867f-491a9c68d9e7","Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack","over-320-npm-packages-hit-by-fresh-mini-shai-hulud-supply-chain-attack-8c7d50","A compromised maintainer account was used to publish malicious package versions across the @antv namespace. The post Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack appeared first on SecurityWeek.","A fresh Mini Shai-Hulud supply chain attack compromised the NPM maintainer account 'atool' to publish malicious versions across 320+ packages in the @antv namespace, including popular libraries like timeago.js (1.5M weekly downloads) and echarts-for-react (1.1M weekly downloads). The campaign spans 1,055 malicious versions across 502 unique packages on NPM, PyPI, and Composer, with obfuscated payloads that steal CI\u002FCD secrets, cloud credentials, and developer tool tokens from over 130 file paths. The malware also injects itself into downstream packages, harvests GitHub Actions runner memory, and provides remote execution capabilities via downloaded Python code, with exfiltration channels suggesting attribution to hacking group TeamPCP.","Over 320 NPM packages compromised in Mini Shai-Hulud supply chain attack via stolen maintainer account.","A fresh Mini Shai-Hulud supply chain attack has hit over 320 NPM packages, along with GitHub Actions and a VS Code extension, security researchers report. The NPM maintainer account ‘atool’, which has access to multiple packages across the @antv namespace, and which publishes timeago.js (1.5 million weekly downloads), was compromised and used to publish malicious package versions. The attack propagated downstream to other highly popular packages, including echarts-for-react (~1.1 million weekly downloads), “impacting a much broader set of applications and continuous integration (CI) environments,” Microsoft warned on Tuesday. According to Socket, roughly 639 malicious versions of the compromised packages were published across “data visualization, graphing, mapping, charting, and React component ecosystems”. “Across the full Mini Shai-Hulud campaign we have tracked 1,055 versions across 502 unique packages. The campaign spans NPM, PyPI, and Composer, with NPM representing the overwhelming majority of the activity: 1,048 NPM versions across 498 unique NPM packages, plus 6 PyPI entries across 3 packages and 1 Composer package-version entry,” Socket notes. Most of the affected packages are in the @antv namespace and contain an install-time payload that triggers a multi-stage infection chain in which payloads are fetched from GitHub-hosted infrastructure. Secondary payloads designed to steal credentials and achieve persistence are also downloaded, Wiz says.Advertisement. Scroll to continue reading. “Every compromised package carries an obfuscated payload that reads GitHub Actions runner process memory to extract masked CI\u002FCD secrets in plaintext, harvests credentials from over 130 file paths covering AWS, GCP, Azure, Kubernetes, HashiCorp Vault, cryptocurrency wallets, and developer tools, then exfiltrates stolen data through two channels,” StepSecurity explains. As with previous Mini Shai-Hulud attacks, the harvested data is exfiltrated through GitHub repositories and through a fallback server, suggesting that the infamous hacking group TeamPCP mounted the attack. “The payload also contains NPM registry abuse logic. It can validate npm tokens through npm registry APIs, enumerate packages maintainable by the token owner, download package tarballs, inject the malicious payload, add a preinstall hook, bump package versions, and republish modified packages under the compromised maintainer’s identity,” Socket says. Unlike the previous campaigns, however, the malware was now seen downloading and executing Python code from the attackers’ infrastructure, “effectively providing the operators with ongoing remote execution capabilities on compromised systems,” Wiz says. StepSecurity also observed the payload dropping persistent backdoors into Claude Code, and identified over 2,200 GitHub repositories containing exfiltrated data. Microsoft’s Durabletask Python SDK was also compromised in the fresh Mini Shai-Hulud campaign, with three malicious versions uploaded to PyPI within a 35-minute window, StepSecurity says. A fresh compromise of the popular GitHub Action actions-cool\u002Fissues-helper can also be linked to this campaign, Wiz says. Related: Real-World ICS Security Tales From the Trenches Related: Virtual Event Today: Threat Detection & Incident Response Summit Related: GitHub Confirms Hack Impacting 3,800 Internal Repositories Related: Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Carnival Data Breach Exposed 6 Million PeopleNew BTMOB Android Malware Enables Full Device TakeoverCritical FortiClient EMS Vulnerability Exploited in Fresh AttacksGitea Vulnerability Exposed 30,000 Deployments to AttacksGoogle Unveils AI Threat Defense Platform to Fight AI-Powered CyberattacksRevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software BinariesGlassWorm Botnet DisruptedFBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data Latest News In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain AttacksCharter Communications Data Breach Could Impact Nearly 5 MillionMokN Raises $15 Million for Phish-Back PlatformGogs Zero-Day Exposes Servers to Remote Code ExecutionCalifornia Sues 23andMe, Alleging It Failed to Protect User Data in 2023 BreachChrome 148 Update Patches 151 VulnerabilitiesRussia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge CyberattacksGeordie Raises $30 Million for AI Security and Governance Platform Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit On-Demand Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the MoveAnurag Jain has been appointed Senior Vice President of Engineering at CodeHunterCTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.More People On The MoveExpert Insights Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fover-320-npm-packages-hit-by-fresh-mini-shai-hulud-supply-chain-attack\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F12\u002Fblockchain-cryptocurrency-Solana.jpeg","2026-05-20T11:06:49+00:00","2026-05-20T12:00:21.09096+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"Mini Shai-Hulud","campaign",{"name":22,"type":23},"TeamPCP","threat_actor",{"name":25,"type":26},"timeago.js","product",{"name":28,"type":26},"echarts-for-react",{"name":30,"type":26},"actions-cool\u002Fissues-helper",{"name":32,"type":26},"Microsoft Durabletask Python SDK","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":33,"icon":35,"name":36,"slug":37},null,"Supply Chain","supply-chain",[39,44,49],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":50},{"id":51,"icon":35,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55],{"type":43,"value":19,"context":56},"Multi-stage supply chain attack campaign targeting NPM, PyPI, and Composer packages with obfuscated payloads for credential theft and persistence"]