Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft

0
Medium
Malwarelinux
Published: 05/20/2026 (05/20/2026, 17:48:44 UTC)
Source: Microsoft Security Blog

Description

Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password platforms. The post Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft appeared first on Microsoft Security Blog .

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 20:28:26 UTC

Technical Analysis

Mini Shai Hulud is a malware payload delivered through compromised @antv npm packages. It activates during the npm install process on Linux-based CI/CD environments and steals credentials from various critical platforms such as GitHub, AWS, Kubernetes, Vault, npm, and 1Password. The malware's goal is to exfiltrate secrets used in automation pipelines, potentially enabling further compromise of development and deployment infrastructure. The threat is documented in a Microsoft Security Blog post dated May 20, 2026. No patch or official remediation details are provided in the source data. The attack vector relies on supply chain compromise of npm packages.

Potential Impact

The malware enables theft of CI/CD credentials across multiple widely used platforms, which could lead to unauthorized access to source code repositories, cloud resources, container orchestration systems, secret management tools, and package registries. This can result in significant operational disruption and potential data breaches in affected environments. However, there is no evidence of active exploitation in the wild as per the provided information.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory and Microsoft Security Blog for current remediation guidance. Until official fixes or package updates are available, users should avoid using the compromised @antv npm packages and consider auditing their CI/CD environments for suspicious activity. Employing strict supply chain security practices, such as verifying package integrity and using trusted sources, is recommended. Monitor for updates from package maintainers and security advisories for any official fixes or mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.microsoft.com/en-us/security/blog/2026/05/20/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/","fetched":true,"fetchedAt":"2026-05-26T20:27:44.204Z","wordCount":2807}

Threat ID: 6a160241e29bf47b505cf02f

Added to database: 05/26/2026, 20:27:45 UTC

Last enriched: 05/26/2026, 20:28:26 UTC

Last updated: 07/30/2026, 21:27:49 UTC

Views: 203

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses