Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (11 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

Snyk Reports Mini Shai-Hulud Attack on AntV with 637 Malicious npm Versions

Share the canonical public link.

Share as image

Snyk published details on May 18, 2026 about the Mini Shai-Hulud supply chain attack hitting the AntV ecosystem. Snyk identified 637 malicious versions across 323 packages published via the compromised atool npm account in a 22-minute automated burst on May 19, 2026 between 01:39 and 02:06 UTC. The attack used preinstall hooks with Bun payloads, optionalDependencies to orphan commits for valid SLSA provenance, and mechanisms for credential harvesting plus self-propagation to C2 at t.m-kosche.com. Snyk issued advisories in its Vulnerability Database and a Zero Day Report for customers while comparing the wave to the prior TanStack incident of May 11, 2026 that affected 84 versions across 42 packages.

Below validation threshold — auto-passed without scoring

Supporting evidence