Socket @socket.dev · May 19

🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @​antv ecosystem. The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool.

40 likes 2 replies

?

Replies

Socket · May 19

This is a developing story. We’ve embedded the affected package list from Socket’s campaign page and will keep updating as more versions and payload details are confirmed. socket.dev/blog/antv-pa...

Connor Shea · May 19

Is it possible they were compromised via the GitHub Actions issues-helper compromise earlier today? www.stepsecurity.io/blog/actions...