Mini Shai-Hulud Malware Infects AntV npm Packages via Compromised Maintainer Accounts
Cybersecurity researchers uncovered a Mini Shai-Hulud supply chain attack targeting the npm ecosystem. Attackers compromised maintainer accounts to push malicious versions of over 300 packages, including widely used @antv libraries like echarts-for-react, @antv/g2, @antv/g6, and others.


The malware harvests credentials for cloud services, GitHub, SSH, Docker, and more, then exfiltrates data while establishing persistence through preinstall hooks and CI/CD abuse. The campaign leverages Sigstore attestation forgery and OIDC token misuse to make malicious releases appear legitimate, amplifying the risk to organizations that auto-update dependencies.
This attack highlights the growing threat of npm supply chain malware, emphasizing the need for credential rotation, two-factor authentication, auditing GitHub accounts, and upgrading to safe package versions to protect sensitive data and enterprise environments.
NPAV offers a robust solution to combat cyber fraud. Protect yourself with our top-tier security product, Z Plus Security
- Other (43)
- Ransomware (179)
- Events and News (28)
- Features (45)
- Security (505)
- Tips (83)
- Google (49)
- Achievements (13)
- Products (37)
- Activation (7)
- Dealers (1)
- Bank Phishing (61)
- Malware Alerts (300)
- Cyber Attack (384)
- Data Backup (15)
- Data Breach (232)
- Phishing (194)
- Securty Tips (9)
- Browser Hijack (30)
- Adware (15)
- Email And Password (90)
- Android Security (98)
- Knoweldgebase (37)
- Botnet (20)
- Updates (12)
- Alert (72)
- Hacking (90)
- Social Media (11)
- vulnerability (133)
- Hacker (107)
- Spyware (18)
- Windows (31)
- Microsoft (48)
- Uber (1)
- YouTube (4)
- Trojan (7)
- Website hacks (17)
- Paytm (1)
- Credit card scam (4)
- Telegram (9)
- RAT (12)
- Bug (5)
- Twitter (3)
- Facebook (14)
- Banking Trojan (17)
- Mozilla (2)
- COVID-19 (5)
- Instagram (5)
- NPAV Announcement (18)
- IoT Security (4)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- Amazon (5)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (5)
- Cloud malware (5)
- Cloud storage (2)
- Financial fraud (115)
- Impersonation phishing (4)
- DDoS (12)
- Smishing (2)
- Whale (0)
- Whale phishing (6)
- WINRAR (3)
- ZIP (2)
- Fraud Protector (101)
-
Mobile Frauds
(80)
- WhatsApp (21)
- AI (42)