A malicious npm worm (Mini Shai-Hulud) compromised 323 packages in under an hour, primarily targeting @antv visualization libraries and echarts-for-react (1.1 million weekly downloads), using preinstall hooks to steal credentials like GitHub tokens, AWS keys, and SSH keys, then exfiltrating data to a server disguised as an OpenTelemetry endpoint; affected systems should pin to known-good versions, rotate credentials, and roll back changes.
深度探索
先修知识
- 暂无数据。
后续步骤
- 暂无数据。
深度探索
Mini Shai-Hulud npm worm hits @antv and echarts-for-react本站添加:
Mini Shai Hulud, the MPM worm that hit TanStack and two Open AI employees last week, is back. Early Tuesday, the worm hit the MPM account of a maintainer called A tool. In under an hour, 323 packages got malicious versions, 639 versions in total. Most are at Ant V packages, visualization libraries used in a lot of React dashboards. Outside at Ant V, the one to flag is ECharts for React, the React wrapper for Apache ECharts. It has 1.1 million weekly downloads. So, if you ran npm install on a project point ECharts for React or anything at Ant V Tuesday morning, you may have grabbed the poison version. The payload tracks with prior waves. A pre-install hook scrapes GitHub tokens, AWS keys, Kubernetes accounts, small tokens, SSH keys, database connection strings, and ships them out.
Socket says the data goes to a server disguised as an OpenTelemetry traces endpoint, which won't look unusual leaving a dev machine or a build server.
If your build pipeline or laptop pulled a fresh at Ant V or ECharts for React version this week, pin to a known good version, rotate any credentials that were on that machine, and then roll back if you need to.
相关推荐
Agentforce NOW AMA: Build with React and Salesforce Multi-Framework
SalesforceDevs
490 views•2026-05-28
How agent o11y differs from traditional o11y — Phil Hetzel, Braintrust
aiDotEngineer
450 views•2026-05-28
WEB TECHNOLOGIES UNIT-2 | Degree 4th sem BCOM Computers web technologies unit-2 full explanation💯✅
LearnwithSahera
1K views•2026-05-29
More tests are always better? How to use AI to identify tests that bring little value
Alliance4Qualification
335 views•2026-05-29
Search Algorithms Explained in 60 Seconds! 🤖💨
samarthtuliofficial
218 views•2026-06-01
People of Game of Thrones using JavaScript DOM
AltCampus
296 views•2026-05-30
Introduction to Problem Solving Part - 1 | Lecture 1 | Intermediate DSA
ascensionix
107 views•2026-05-29
🚀 BCS613C Compiler Design | Module 1 to 5 Schema Evaluation 🔥 | VTU 6th Sem 💯 #VTU #bcs613c #exam
Pranavaa-y4y
104 views•2026-06-02











