Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
Reported 20 May 2026 by otx · Severity: medium
Microsoft identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv maintainer account and published malicious versions of widely used data-visualization packages, affecting libraries like echarts-for-react with over 1