The Mini Shai-Hulud npm worm has hit Alibaba’s @antv packages, echarts-for-react, and timeago.js. The payload steals CI/CD secrets, plants backdoors in VS Code and Claude Code, and spreads by republishing compromised packages. Here is what happened and how to protect your team.
Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages
calendar_today
May 19, 2026
domain
aikido-security