A Day in the Life of a Strategy Co-Op in Snyk’s Boston Office

2026-05-20T20:51:59Zbe7956dc2230ed028a0d1f05f85bd8e421a575afdea927a28aa0066b8ac2ac48
antvcache-poisoningcompromised-maintainerdurabletaskgithub-actionsincident-responsemalicious-packagesmalwaremini-shai-huludnode-ipcnpmoidc-token-extractionpypislsasoftware-supply-chainsupply-chaintanstack

What happened

Between May 11–20, 2026 an active supply‑chain campaign dubbed “Mini Shai‑Hulud” and related activity rapidly expanded across ecosystems. Initial compromises (TanStack on May 11) used a GitHub Actions “Pwn Request”, cache‑poisoning and OIDC token extraction from runner memory to push malicious npm artifacts with valid SLSA attestation. Subsequent waves included node‑ipc (malicious npm versions published), a surge of 300+ malicious AntV npm package versions via a compromised maintainer account, and lateral movement to PyPI by compromising Microsoft‑associated durabletask. Snyk is tracking the事件

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
be7956dc2230ed028a0d1f05f85bd8e421a575afdea927a28aa0066b8ac2ac48
Enrichment time
2026-05-20T20:51:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.