people · May 21, 2026
Snyk Reports Mini Shai-Hulud Attack on AntV with 637 Malicious npm Versions
Share the canonical public link.
Snyk published details on May 18, 2026 about the Mini Shai-Hulud supply chain attack hitting the AntV ecosystem. Snyk identified 637 malicious versions across 323 packages published via the compromised atool npm account in a 22-minute automated burst on May 19, 2026 between 01:39 and 02:06 UTC. The attack used preinstall hooks with Bun payloads, optionalDependencies to orphan commits for valid SLSA provenance, and mechanisms for credential harvesting plus self-propagation to C2 at t.m-kosche.com. Snyk issued advisories in its Vulnerability Database and a Zero Day Report for customers while comparing the wave to the prior TanStack incident of May 11, 2026 that affected 84 versions across 42 packages.