Active npm supply-chain attack compromises @antv packages, uses Shai-Hulud clones

An active npm supply-chain attack published hundreds of malicious package versions from the compromised maintainer account 'atool' on May 19, 2026, impacting core @antv packages and related libraries. The malware (Shai-Hulud and clones) steals developer secrets and cloud credentials, establishes C2 persistence, and self-propagates via stolen npm tokens; separate actors published additional Shai-Hulud-based malicious packages and typosquats. Researchers from Snyk, Ox Security, Socket, and others detected the automated publish waves and classified the affected versions as known malware.

Part of the PlainSec briefing for 2026-05-18

Sources