Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
As part of the continuing Mini Shai-Hulud assault wave, cybersecurity experts have found a new software supply chain attack operation that has compromised several npm packages connected to the @antv ecosystem.
According to Socket, the assault targets packages linked to the npm maintainer account atool, such as echarts-for-react, a popular React wrapper for Apache ECharts that receives about 1.1 million downloads every week.
In addition to related packages outside the @antv namespace, such as echarts-for-react, timeago.js, size-sensor, canvas-nest.js, and others, the list of impacted packages includes @antv packages like @antv/g2, @antv/g6, @antv/x6, @antv/l7, @antv/s2, @antv/f2, @antv/g, @antv/g2plot, @antv/graphin, and @antv/data-set.
According to the application security busine...

