Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mini Shai-Hulud Attack Targets 320+ NPM Packages

Mini Shai-Hulud Attack Targets 320+ NPM Packages

Posted on May 20, 2026 By CWS

A recent cyber attack dubbed Mini Shai-Hulud has compromised over 320 NPM packages, along with GitHub Actions and a Visual Studio Code extension, according to security researchers. This incident highlights the vulnerability of software supply chains.

NPM Maintainer Account Breach

The attack was traced back to the compromise of the NPM maintainer account ‘atool’, which managed several packages under the @antv namespace, including the widely-used timeago.js with 1.5 million weekly downloads. The compromised account was used to release malicious versions of these packages.

This breach extended its reach to popular packages like echarts-for-react, affecting a broader spectrum of applications and continuous integration environments. Microsoft issued a warning about the potential widespread impact on Tuesday.

Widespread Impact and Propagation

Security firm Socket reported that approximately 639 malicious versions spanned ecosystems in data visualization, graphing, mapping, charting, and React components. The larger campaign involved 1,055 versions across 502 unique packages, primarily affecting NPM but also incorporating PyPI and Composer.

The attack primarily targeted packages within the @antv namespace, deploying an install-time payload that initiated a multi-stage infection chain. This process involved fetching additional payloads from GitHub-hosted infrastructure, which were designed to steal credentials and ensure persistence.

Data Exfiltration and Remote Execution

The malicious code was engineered to extract sensitive data from GitHub Actions runner memory, targeting CI/CD secrets, and credentials from over 130 file paths, including cloud services and developer tools. Data exfiltration was conducted via GitHub repositories and fallback servers, linking the attack to the notorious TeamPCP group.

New to this campaign was the malware’s ability to execute Python code from attackers’ infrastructure, granting remote control over compromised systems. This capability was observed by Wiz, indicating an evolution in the attack’s complexity.

StepSecurity noted the deployment of persistent backdoors into Claude Code, and identified over 2,200 GitHub repositories containing exfiltrated data. Additionally, Microsoft’s Durabletask Python SDK was compromised, with three malicious versions uploaded to PyPI within a short timeframe.

The campaign also compromised the popular GitHub Action actions-cool/issues-helper, emphasizing the need for heightened security measures across software ecosystems.

As cyber threats continue to evolve, organizations must prioritize securing their supply chains to prevent similar incidents in the future.

Security Week News Tags:Cybersecurity, data exfiltration, GitHub actions, Malware, Mini Shai-Hulud, npm packages, Python code, supply chain attack, TeamPCP, VS Code

Post navigation

Previous Post: AI-Powered Typosquatting Threatens Supply Chains
Next Post: Critical NGINX Flaw Risks Remote Code Execution

Related Posts

Imper.ai Emerges From Stealth Mode With  Million in Funding Imper.ai Emerges From Stealth Mode With $28 Million in Funding Security Week News
Vulnerability in OpenAI Coding Agent Could Facilitate Attacks on Developers Vulnerability in OpenAI Coding Agent Could Facilitate Attacks on Developers Security Week News
Grafana Patches Chromium Bugs, Including Zero-Day Exploited in the Wild Grafana Patches Chromium Bugs, Including Zero-Day Exploited in the Wild Security Week News
Thousands of Secrets Leaked on Code Formatting Platforms Thousands of Secrets Leaked on Code Formatting Platforms Security Week News
Exploit Released for Unpatched Windows Vulnerability Exploit Released for Unpatched Windows Vulnerability Security Week News
Google API Keys in Android Apps Risk Data Breach Google API Keys in Android Apps Risk Data Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Boosts Cyber Threats in App Security Landscape
  • Is Your Business Prepared for Agent AI Challenges?
  • Microsoft Python SDK Compromised by TeamPCP Hackers
  • 1Password and OpenAI Enhance Security for AI Coding Tools
  • Webworm Uses Discord and MS Graph for New Backdoors

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Boosts Cyber Threats in App Security Landscape
  • Is Your Business Prepared for Agent AI Challenges?
  • Microsoft Python SDK Compromised by TeamPCP Hackers
  • 1Password and OpenAI Enhance Security for AI Coding Tools
  • Webworm Uses Discord and MS Graph for New Backdoors

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark