Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft

2026-05-20T20:52:17Zba687ddc36f3ca125fa3e9af258dd46fadd6fc12b0233d4e66b4916c6d20299f
1Password@antvAWSCI/CDGitHubHashiCorp VaultKubernetesLinuxMini Shai-Huludcompromised-packagecredential-theftmalwarenpmnpm-installpackage-tamperingsecrets-exfiltrationsupply-chain

What happened

Microsoft reports a supply‑chain compromise of several @antv npm packages that deploy the “Mini Shai‑Hulud” payload during npm install on Linux CI/CD runners. The malware harvests and exfiltrates CI/CD secrets and tokens from automation environments, targeting GitHub, AWS, Kubernetes, HashiCorp Vault, npm, 1Password and other credential stores, enabling further cloud and pipeline takeover. Attack vector is malicious/compromised npm packages executing at install time; mitigation focuses on protecting CI runners, secret hygiene, and supply‑chain controls.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
ba687ddc36f3ca125fa3e9af258dd46fadd6fc12b0233d4e66b4916c6d20299f
Enrichment time
2026-05-20T20:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft · Baitaphish