A Day in the Life of a Strategy Co-Op in Snyk’s Boston Office
2026-05-20T20:51:59Z•be7956dc2230ed028a0d1f05f85bd8e421a575afdea927a28aa0066b8ac2ac48
antvcache-poisoningcompromised-maintainerdurabletaskgithub-actionsincident-responsemalicious-packagesmalwaremini-shai-huludnode-ipcnpmoidc-token-extractionpypislsasoftware-supply-chainsupply-chaintanstack
What happened
Between May 11–20, 2026 an active supply‑chain campaign dubbed “Mini Shai‑Hulud” and related activity rapidly expanded across ecosystems. Initial compromises (TanStack on May 11) used a GitHub Actions “Pwn Request”, cache‑poisoning and OIDC token extraction from runner memory to push malicious npm artifacts with valid SLSA attestation. Subsequent waves included node‑ipc (malicious npm versions published), a surge of 300+ malicious AntV npm package versions via a compromised maintainer account, and lateral movement to PyPI by compromising Microsoft‑associated durabletask. Snyk is tracking the事件
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- be7956dc2230ed028a0d1f05f85bd8e421a575afdea927a28aa0066b8ac2ac48
- Enrichment time
- 2026-05-20T20:51:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.