Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Massive npm Supply Chain Attack Targets Antv Packages

Massive npm Supply Chain Attack Targets Antv Packages

Posted on May 19, 2026 By CWS

The npm ecosystem has been rocked by a major supply chain attack, compromising hundreds of JavaScript packages associated with the @antv data visualization library. This widespread breach, which occurred on May 19, 2026, has affected millions of developers globally by inserting malicious code into popular packages.

Scope of the npm Breach

The attack was orchestrated through a compromised npm maintainer account, ‘atool’, which was used to distribute infected versions of well-known packages. Notably, the widely-used echarts-for-react package, which records about 1.1 million weekly downloads, was among the impacted packages. The breach extended beyond @antv packages, affecting other unrelated packages like timeago.js and canvas-nest.js, marking it as one of the largest incidents in recent npm history.

Detection and Analysis

Researchers at Socket.dev quickly identified the malicious activity, categorizing affected versions as malware within minutes of their release. According to a report shared with Cyber Security News (CSN), 639 compromised package versions were detected across 323 unique packages during what was termed the ‘5/19 Mini Shai-Hulud wave’. The broader campaign tracked by Socket.dev includes 1,055 versions spanning npm, PyPI, and Composer registries, with the npm ecosystem bearing the brunt of the attack.

Technical Details and Impact

The malicious code is linked to the Mini Shai-Hulud malware family and is designed to execute payloads during package installation. It employs a sophisticated encryption scheme to conceal data exfiltration, targeting sensitive developer and CI/CD environment information like GitHub tokens and AWS credentials. If a GitHub token is acquired, the malware can use GitHub’s infrastructure for data exfiltration, making detection challenging. Approximately 1,900 repositories associated with this campaign have been identified, employing Dune-themed names as identification markers.

Organizations affected by this breach should immediately review and audit package updates from the @antv and related npm namespaces. Rotating credentials and scrutinizing CI/CD logs for unauthorized GitHub activity are strongly recommended to mitigate potential damage.

Indicators of Compromise (IoCs) have been shared to assist in identifying affected systems. These include specific domains, URLs, and GitHub repository patterns linked to the attack. Developers are urged to stay vigilant and secure their environments against further threats.

Stay updated on the latest developments by following us on Google News, LinkedIn, and X. Make CSN your preferred news source on Google for immediate updates.

Cyber Security News Tags:AntV, Cybersecurity, data breach, data visualization, developer tools, GitHub, JavaScript, malicious code, Malware, NPM, open source security, Socket.dev, Software Security, supply chain attack, threat actor

Post navigation

Previous Post: Compromised Nx Console Targets VS Code with Credential Theft
Next Post: DirtyDecrypt Vulnerability Exposes Linux Kernel Risk

Related Posts

ChainDrop Worm Targets npm Packages for Credential Theft ChainDrop Worm Targets npm Packages for Credential Theft Cyber Security News
15 Best Remote Monitoring Tools 15 Best Remote Monitoring Tools Cyber Security News
Malicious Outlook Add-in Exposes 4,000 Accounts Malicious Outlook Add-in Exposes 4,000 Accounts Cyber Security News
SILENTCONNECT Malware Threatens Windows Security SILENTCONNECT Malware Threatens Windows Security Cyber Security News
10 Malicious npm Packages with Auto-Run Feature on Install Deploys Multi-Stage Credential Harvester 10 Malicious npm Packages with Auto-Run Feature on Install Deploys Multi-Stage Credential Harvester Cyber Security News
Critical AWS-LC Vulnerabilities Expose Security Risks Critical AWS-LC Vulnerabilities Expose Security Risks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security
  • Red Hat Satellite Flaw: Risk of Root Password Theft
  • Hackers Exploit Software Updates for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenClaw Unveils Free AI Agent Management Platform
  • Critical GitLab AI Gateway Vulnerability Patched
  • Critical cPanel/WHM Flaws Risk Server Security
  • Red Hat Satellite Flaw: Risk of Root Password Theft
  • Hackers Exploit Software Updates for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark