Microsoft: Mini Shai-Hulud npm supply-chain attack targeting antv packages

Attackers compromised an antv maintainer account and published malicious versions of widely used npm packages, extending the Shai-Hulud-style supply-chain pattern

Microsoft is investigating a new, emerging Mini Shai-Hulud npm supply chain attack targeting antv packages. Attackers compromised an antv maintainer account and published malicious versions of multiple widely used packages (for example, a
Ranked #7 on backlist 2026-05-19 (19 May 2026 UTC) · by (Microsoft Threat Intelligence) ·

How it ranks: Backlist reads my Twitter/X timeline, scores every tweet for substance with an LLM rubric (not engagement), and publishes the daily top picks with a one-line takeaway. Curated by Surya Dantuluri.