Attackers Launch Large-Scale 'Mini Shai-Hulud' Supply Chain Attack, Compromising 637 npm Package Versions in 22 Minutes on May 19

GateNews

According to Slowmist, on May 19-20, attackers compromised the npm account atool and automatically published 637 malicious versions across 317 packages within 22 minutes. Between 00:19 and 00:54 Beijing time on May 20, attackers uploaded durabletask versions 1.4.1, 1.4.2, and 1.4.3, impersonating Microsoft's official releases.

Affected high-frequency components include AntV and Echarts-for-react in npm ecosystem, and durabletask in Python. Slowmist linked the GitHub token mass leak and Grafana Labs ransomware attacks to this campaign. Attackers could steal credentials, gain unauthorized access to internal repositories, move laterally through CI/CD pipelines, and extort organizations using compromised GitHub tokens.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments