PULSE NAME
Active Supply Chain Attack Compromises Packages on npm
WHITE AlienVault 2026-05-19 Modified: 2026-05-19
3
IOCs
LOW VOLUME
An active npm supply chain attack has compromised packages in the @antv ecosystem, affecting the maintainer account 'atool'. The attack is part of the Mini Shai-Hulud campaign, involving 639 compromised package versions across 323 unique packages. Notable affected packages include echarts-for-react with 1.1 million weekly downloads, and widely-used @antv packages for data visualization. The malware uses obfuscated install-time payloads that harvest developer credentials, GitHub tokens, npm tokens, AWS credentials, and other secrets from development and CI/CD environments. Stolen data is encrypted with AES-256-GCM and exfiltrated to a command-and-control server, with GitHub repositories used as fallback channels. The malware contains worm-like functionality to republish compromised packages and propagate through the npm ecosystem.
Indicators of Compromise (1 / 3 total)
All FileHash-SHA1 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 1916faa365f2788b6e193514872d51a242876569 2026-05-19