National Cyber Warfare Foundation (NCWF)

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account


0 user ratings
2026-05-19 05:34:09
milo
Blue Team (CND)
Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave.

"The attack affects packages tied to the npm maintainer account atool, including echarts-for-react, a widely used React wrapper for Apache ECharts with roughly 1.1 million weekly



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/05/mini-shai-hulud-pushes-malicious-antv.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.