news.mlab.sh
Back to the feed
supply-chain

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

High
Image: The Hacker News
Summary

A sophisticated supply chain attack, dubbed Mini Shai-Hulud, is targeting npm packages within the @antv ecosystem. The attack leverages a compromised maintainer account to inject malicious code – specifically a credential-stealing payload – into numerous open-source packages, including widely used React components. This campaign, attributed to TeamPCP, utilizes automated techniques like stolen npm tokens and Sigstore forgery to rapidly propagate the malware and exfiltrate sensitive data, posing a significant risk to organizations relying on these vulnerable packages.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.