As part of the continuing Mini Shai-Hulud assault wave, cybersecurity experts have found a new software supply chain attack operation that has compromised several npm packages connected to the @antv ecosystem.
According to Socket, the assault targets packages linked to the npm maintainer account atool, such as echarts-for-react, a popular React wrapper for Apache ECharts that receives about 1.1 million downloads every week.
In addition to related packages outside the @antv namespace, such as echarts-for-react, timeago.js, size-sensor, canvas-nest.js, and others, the list of impacted packages includes @antv packages like @antv/g2, @antv/g6, @antv/x6, @antv/l7, @antv/s2, @antv/f2, @antv/g, @antv/g2plot, @antv/graphin, and @antv/data-set.
According to the application security business, the tradecraft is similar to Mini Shai-Hulud, which uses a hacked maintainer account to quickly release trojanized versions.
The development coincides with the supply chain attack campaign’s ongoing slithering across read more about Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
