Attackers linked by multiple researchers to TeamPCP hijacked the npm maintainer account atool and used it to publish roughly 639 malicious versions across 323 packages, heavily impacting Alibaba’s @antv/* ecosystem as well as packages such as echarts-for-react, timeago.js, and size-sensor. Reports said the malware executed through malicious preinstall hooks and an obfuscated Bun-based payload, stealing secrets from developer workstations and CI/CD systems including GitHub, npm, AWS, Kubernetes, Vault, SSH, Docker, and database credentials. The campaign also abused GitHub tokens to create attacker-controlled repositories for exfiltration, scraped GitHub Actions runner memory for plaintext secrets, and in some cases targeted trusted tooling including a briefly compromised Nx Console VS Code extension.
Researchers said the operation was worm-like and self-propagating, using stolen npm tokens to tamper with and republish additional packages under legitimate maintainer identities, with the broader Mini Shai-Hulud activity now tracked across npm, PyPI, and Composer. The malware reportedly established persistence in developer environments through modified VS Code and Claude Code settings and OS-level services, while some reports warned it also attempted to forge valid Sigstore/SLSA provenance using stolen CI identities. In response, npm invalidated all write-enabled granular access tokens that bypassed two-factor authentication and introduced Staged Publishing in preview, but researchers warned that any machine or pipeline that installed affected versions should be treated as fully compromised and all reachable credentials rotated immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that a malicious Nx Console VS Code extension was available briefly and sought GitHub, AWS, Kubernetes, Vault, and Claude Code credentials while attempting persistence and provenance forgery. SC Media states the extension was live for 11 minutes during the campaign.
Researchers described the AntV/npm activity as the third wave of an ongoing credential-chain operation that began in March and linked it to TeamPCP. This establishes the broader Mini Shai-Hulud campaign predating the May npm wave.
npm introduced Staged Publishing in public preview, adding an MFA-approved staging step before CI-published packages become publicly installable. Reporting explicitly dates this mitigation rollout to May 20.
In response to the supply-chain attacks, npm invalidated all granular access tokens with write access that bypassed two-factor authentication. The action was explicitly reported as taking place on May 19.
After the initial atool takeover, the malware used stolen npm tokens to enumerate publishable packages, inject itself, and republish them under additional maintainer accounts. OpenSourceMalware reported @starmind/collector-cli was compromised this way, not directly through atool.
Using the compromised maintainer account, attackers published roughly 637-639 malicious versions across 317-323 npm packages, heavily affecting Alibaba's @antv ecosystem along with packages such as echarts-for-react and timeago.js. Reports describe the burst as occurring within minutes and as part of a single overnight wave.
The Mini Shai-Hulud npm wave was triggered by the compromise of the legitimate npm maintainer account 'atool'. Multiple reports identify this account takeover as the immediate precursor to the malicious package publishing spree.
Researchers said the broader campaign had already compromised 42 TanStack packages before the AntV wave. This earlier incident was explicitly anchored to May 11 in reporting on the later npm response.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesocket.dev
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcesnyk.io
Open sourceopensourcemalware.com
Open sourcephoenix.security
Open sourcekb.cert.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.