What is Mini Shai-Hulud npm supply chain attack, and was Microsoft and Socket hit by malware? A new software supply chain attack has affected the npm ecosystem and raised concern across developer and security communities. The attack targeted packages linked to the @antv ecosystem and spread into downstream tools and applications. Security researchers confirmed that hundreds of malicious package versions were published in a short time window. The malware focused on credential theft and propagation through CI/CD pipelines and repositories. Microsoft Defender detected malicious activity, while Socket began investigating the compromised packages. The incident highlights risks in dependency management and automated package updates.
What is Mini Shai-Hulud npm supply chain attack, and was Microsoft and Socket hit by malware?
The Mini Shai-Hulud npm supply chain attack is a malware campaign that used compromised npm accounts to publish infected package versions. These packages spread into many applications through dependencies and CI/CD pipelines. The malware focused on stealing credentials and spreading across repositories. Microsoft confirmed detections through Microsoft Defender, and Socket confirmed investigation of the compromised packages and the large attack wave affecting the @antv ecosystem.
Microsoft confirmed it is investigating an emerging npm supply chain attack targeting antv packages. The incident involves compromised packages, credential theft, and worm-like propagation across repositories and development environments.