Attackers abused the npm account atool—linked to the maintainer of timeago.js and with publish rights across Alibaba’s AntV ecosystem—to push malicious releases into widely used JavaScript packages. Reporting from StepSecurity, SafeDep, Aikido Security, and CSO indicates the campaign affected packages including timeago.js, echarts-for-react, size-sensor, and numerous @antv/* libraries used for charting, graphing, rendering, mapping, and spreadsheet functions in web applications and dashboards.
Researchers said the attacker published malicious code at scale, with one account citing 637 malicious versions across 317 packages in about 22 minutes, while another identified 143 compromised packages with affected versions. The payload was described as a CI/CD credential stealer and linked by some researchers to the Mini-Shai-Hulud worm, raising concern because the infected packages are commonly pulled into front-end builds and automated pipelines such as GitHub Actions, GitLab CI, and Kubernetes-hosted CI systems, where exposed tokens and cloud credentials could enable broader downstream compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
In response to the Mini-Shai-Hulud npm supply-chain campaign, GitHub removed 640 malicious packages from npm and invalidated 61,274 npm granular access tokens that had write permissions and 2FA bypass enabled. The action was part of containment after the compromised @antv ecosystem packages were found distributing credential-stealing malware.
Wiz reported that the TeamPCP-linked supply-chain campaign also compromised the GitHub Action actions-cool/issues-helper and the VSCode extension nrwl.angular-console version 18.95.0, extending the operation beyond malicious npm packages. The report also described a persistent Python backdoor that polled GitHub for signed commands containing the trigger string "firedalazer."
OX Security reported that the renewed Shai-Hulud npm supply-chain campaign was likely linked to TeamPCP and described the operation as financially motivated. The assessment was based in part on alleged social-media posts tied to the group, adding a new attribution angle to the incident.
Endor Labs reported that the May 19 Mini Shai-Hulud npm campaign could generate apparently legitimate Sigstore provenance by minting OIDC tokens, obtaining Fulcio certificates, and creating Rekor log entries. The finding showed that malicious packages in the AntV-related supply-chain attack could appear properly signed, undermining provenance-only trust decisions.
Security firms including SafeDep, Aikido Security, and StepSecurity said the malicious npm releases delivered the Mini-Shai-Hulud worm or a CI/CD credential stealer. The malware was described as targeting high-value build and cloud environments such as GitHub Actions, GitLab CI, and Kubernetes-hosted pipelines.
OpenSourceMalware reported that the May 19 npm supply-chain campaign affected not only the atool maintainer account but also the npm account "prop," with 324 packages republished as 645 package-version artifacts across two clustered publish waves. The report said the affected packages represented more than 16 million weekly downloads and highlighted broad downstream risk to developer and CI/CD environments.
Researchers reported that malicious releases affected timeago.js, echarts-for-react, size-sensor, @antv/scale, and a broad set of Alibaba AntV packages. StepSecurity said 143 packages were compromised and listed affected versions, indicating broad downstream exposure in front-end builds and CI/CD environments.
An attacker used the compromised npm account "atool" (i@hust.cc), which had publish rights across timeago.js and many AntV-related packages, to push malicious code at scale. SafeDep reported at least 637 malicious versions across 317 packages were published within a 22-minute window.
The source code for the Mini-Shai-Hulud npm malware was reportedly briefly exposed on GitHub, enabling other criminals to reuse it in later supply-chain attacks.
TrustedSec reported that credentials harvested by the Shai-Hulud/Mini-Shai-Hulud npm malware were actively abused, with more than 2,200 public GitHub repositories created using stolen tokens and named with Dune-themed terminology. The report also detailed persistence via Node.js preload backdoors in VS Code and Claude Code configurations and exfiltration through the GitHub API and t.m-kosche.com.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
14 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesafedep.io
Open sourcemicrosoft.com
Open sourceopensourcemalware.com
Open sourcetrustedsec.com
Open sourcesecurity.snyk.io
Open sourcesecurity.snyk.io
Open sourcesecurity.snyk.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.