A malicious npm worm (Mini Shai-Hulud) compromised 323 packages in under an hour, primarily targeting @antv visualization libraries and echarts-for-react (1.1 million weekly downloads), using preinstall hooks to steal credentials like GitHub tokens, AWS keys, and SSH keys, then exfiltrating data to a server disguised as an OpenTelemetry endpoint; affected systems should pin to known-good versions, rotate credentials, and roll back changes.
深掘り
前提条件
- データがありません。
次のステップ
- データがありません。
深掘り
Mini Shai-Hulud npm worm hits @antv and echarts-for-react追加:
Mini Shai Hulud, the MPM worm that hit TanStack and two Open AI employees last week, is back. Early Tuesday, the worm hit the MPM account of a maintainer called A tool. In under an hour, 323 packages got malicious versions, 639 versions in total. Most are at Ant V packages, visualization libraries used in a lot of React dashboards. Outside at Ant V, the one to flag is ECharts for React, the React wrapper for Apache ECharts. It has 1.1 million weekly downloads. So, if you ran npm install on a project point ECharts for React or anything at Ant V Tuesday morning, you may have grabbed the poison version. The payload tracks with prior waves. A pre-install hook scrapes GitHub tokens, AWS keys, Kubernetes accounts, small tokens, SSH keys, database connection strings, and ships them out.
Socket says the data goes to a server disguised as an OpenTelemetry traces endpoint, which won't look unusual leaving a dev machine or a build server.
If your build pipeline or laptop pulled a fresh at Ant V or ECharts for React version this week, pin to a known good version, rotate any credentials that were on that machine, and then roll back if you need to.
関連おすすめ
resume fixed instantly 😭 Comment “app”andI’ll sendyou the link #parakeetaipartnership #resumetips
Ritcareer
686 views•2026-05-31
Re: 🗣️📍theprophedu📍2026 GST 103 CLASS (E-EXAM REVISION)
theprophedu
636 views•2026-06-04
3D Basics in C
HirschDaniel
2K views•2026-06-05
Search Algorithms Explained in 60 Seconds! 🤖💨
samarthtuliofficial
218 views•2026-06-01
Making Minecraft Clone with C++ & Raylib
PecaCSLive
686 views•2026-06-04
People of Game of Thrones using JavaScript DOM
AltCampus
296 views•2026-05-30
Instagram accounts got PWNed
EricParker
13K views•2026-06-03
So What's Odin Lang Even Good For
TechOverTea
131 views•2026-06-01











