Active Supply Chain Attack Compromises Packages on npm
Reported 19 May 2026 by otx · Severity: medium
An active npm supply chain attack has compromised packages in the @antv ecosystem, affecting the maintainer account 'atool'. The attack is part of the Mini Shai-Hulud campaign, involving 639 compromised package versions across 323 unique packages. Notable affected packages includ