All updates
Written by May 20, 2026

security: Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft

May 20, 2026

Microsoft reports that compromised @antv npm packages were used to deploy the Mini Shai-Hulud payload, which runs during npm install and steals CI/CD secrets from Linux-based automation environments. The malware targets credentials from GitHub, AWS, Kubernetes, Vault, npm, and 1Password.

Sponsored by GitAds