Attackers linked by multiple researchers to TeamPCP hijacked the npm maintainer account atool and used it to publish roughly 639 malicious versions across 323 packages, heavily impacting Alibaba’s @antv/* ecosystem as well as packages such as echarts-for-react, timeago.js, and size-sensor. Reports said the malware executed through malicious preinstall hooks and an obfuscated Bun-based payload, stealing secrets from developer workstations and CI/CD systems including GitHub, npm, AWS, Kubernetes, Vault, SSH, Docker, and database credentials. The campaign also abused GitHub tokens to create attacker-controlled repositories for exfiltration, scraped GitHub Actions runner memory for plaintext secrets, and in some cases targeted trusted tooling including a briefly compromised Nx Console VS Code extension.
Researchers said the operation was worm-like and self-propagating, using stolen npm tokens to tamper with and republish additional packages under legitimate maintainer identities, with the broader Mini Shai-Hulud activity now tracked across npm, PyPI, and Composer. The malware reportedly established persistence in developer environments through modified VS Code and Claude Code settings and OS-level services, while some reports warned it also attempted to forge valid Sigstore/SLSA provenance using stolen CI identities. In response, npm invalidated all write-enabled granular access tokens that bypassed two-factor authentication and introduced Staged Publishing in preview, but researchers warned that any machine or pipeline that installed affected versions should be treated as fully compromised and all reachable credentials rotated immediately.

Trace attribution and downstream blast radius.
8 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that a malicious Nx Console VS Code extension was available briefly and sought GitHub, AWS, Kubernetes, Vault, and Claude Code credentials while attempting persistence and provenance forgery. SC Media states the extension was live for 11 minutes during the campaign.
Researchers described the AntV/npm activity as the third wave of an ongoing credential-chain operation that began in March and linked it to TeamPCP. This establishes the broader Mini Shai-Hulud campaign predating the May npm wave.
npm introduced Staged Publishing in public preview, adding an MFA-approved staging step before CI-published packages become publicly installable. Reporting explicitly dates this mitigation rollout to May 20.
In response to the supply-chain attacks, npm invalidated all granular access tokens with write access that bypassed two-factor authentication. The action was explicitly reported as taking place on May 19.
After the initial atool takeover, the malware used stolen npm tokens to enumerate publishable packages, inject itself, and republish them under additional maintainer accounts. OpenSourceMalware reported @starmind/collector-cli was compromised this way, not directly through atool.
Using the compromised maintainer account, attackers published roughly 637-639 malicious versions across 317-323 npm packages, heavily affecting Alibaba's @antv ecosystem along with packages such as echarts-for-react and timeago.js. Reports describe the burst as occurring within minutes and as part of a single overnight wave.
The Mini Shai-Hulud npm wave was triggered by the compromise of the legitimate npm maintainer account 'atool'. Multiple reports identify this account takeover as the immediate precursor to the malicious package publishing spree.
Researchers said the broader campaign had already compromised 42 TanStack packages before the AntV wave. This earlier incident was explicitly anchored to May 11 in reporting on the later npm response.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
12 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesocket.dev
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceinfoworld.com
Open sourceopensourcemalware.com
Open sourcephoenix.security
Open sourcekb.cert.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.