Mini Shai-Hulud Worm Targets @antv NPM Packages
Score: 9/10

Mini Shai-Hulud Worm Targets @antv NPM Packages

The Mini Shai-Hulud worm was deployed via compromised @antv npm packages to exfiltrate developer secrets and propagate to other repositories.

Executive Summary

A widespread supply chain attack has been identified involving the @antv npm ecosystem, attributed to the compromised or malicious maintainer account 'atool'. The attack utilizes the 'Mini Shai-Hulud' worm, which was published in malicious versions across hundreds of packages between May 19, 2026. The worm is designed to steal highly sensitive developer and CI/CD secrets, including GitHub and npm tokens, AWS credentials, and SSH keys, often by reading plaintext secrets directly from process memory.

The worm exhibits self-propagating behavior by using stolen npm tokens to publish malicious updates to other packages the victim has access to. It employs sophisticated evasion techniques, including heavy obfuscation and a 'dead-man switch' wiper functionality that deletes user data if exfiltration repositories are removed. This campaign significantly impacts the software supply chain by abusing trusted dependencies to gain access to downstream environments.

Organizations using @antv or related dependencies should immediately audit their environments for the identified IOCs, revoke potentially compromised tokens, and implement stricter package validation processes.

Key Details

Threat Name

Mini Shai-Hulud

Affects

—

Adversary

atool

Malware/Tools

Mini Shai-Hulud

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance6
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources