# npm malware

Published articles for npm malware.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Mini Shai-Hulud npm Attack: AntV Ecosystem Compromise (May 2026)

DevFeed: [Mini Shai-Hulud npm Attack: AntV Ecosystem Compromise (May 2026)](<https://devfeed.tech/articles/mini-shai-hulud-npm-attack-antv-ecosystem-compromise-may-2026-13160.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mini-shai-hulud-npm-attack-antv-ecosystem-compromise-may-2026>)

Published: 2026-05-19T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Data visualization](<https://devfeed.tech/topics/data-visualization.md>), [Aeternum](<https://devfeed.tech/topics/aeternum.md>), [stripe](<https://devfeed.tech/topics/stripe.md>), [Raycast extension](<https://devfeed.tech/topics/raycast-extension.md>), [React UI animations](<https://devfeed.tech/topics/react-ui-animations.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [antv](<https://devfeed.tech/tags/antv.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-npm](<https://devfeed.tech/tags/chainguard-npm.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [react](<https://devfeed.tech/tags/react.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article reports that a compromised npm maintainer account pushed malicious versions of 314 packages in Alibaba's AntV ecosystem on May 19, 2026. It describes the Mini Shai-Hulud campaign, which uses install hooks and obfuscated Bun scripts to deliver malware and harvest developer credentials.

### Source excerpt

The Mini Shai-Hulud npm worm compromised 314 packages in the AntV ecosystem on May 19, 2026 -- including echarts-for-react and timeago.js.

## Node-ipc compromised: Credential stealer targets package with 500k+ weekly downloads

DevFeed: [Node-ipc compromised: Credential stealer targets package with 500k+ weekly downloads](<https://devfeed.tech/articles/node-ipc-compromised-credential-stealer-targets-package-with-500k-weekly-downloads-13188.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/node-ipc-compromised-credential-stealer-targets-package-with-500k-weekly-downloads>)

Published: 2026-05-14T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [CommonJS](<https://devfeed.tech/topics/commonjs.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [claude](<https://devfeed.tech/tags/claude.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [commonjs](<https://devfeed.tech/tags/commonjs.md>), [dns](<https://devfeed.tech/tags/dns.md>), [github](<https://devfeed.tech/tags/github.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [node](<https://devfeed.tech/tags/node.md>), [node-ipc](<https://devfeed.tech/tags/node-ipc.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [node-malware](<https://devfeed.tech/tags/node-malware.md>), [node-worm](<https://devfeed.tech/tags/node-worm.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [security](<https://devfeed.tech/tags/security.md>), [sha-256](<https://devfeed.tech/tags/sha-256.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

Three malicious versions of the node-ipc npm package harvested and exfiltrated credentials from cloud providers, SSH, Kubernetes, CI/CD, version-control tools, and AI APIs. The article reports that Chainguard customers were not affected.

### Source excerpt

Malicious node-ipc packages stole cloud, SSH, Kubernetes, and AI keys. Chainguard customers stayed protected through source-built libraries.

## Chainguard artifacts safe from npm supply chain attack targeting SAP developer dependencies with 2.25M+ monthly downloads

DevFeed: [Chainguard artifacts safe from npm supply chain attack targeting SAP developer dependencies with 2.25M+ monthly downloads](<https://devfeed.tech/articles/chainguard-artifacts-safe-from-npm-supply-chain-attack-targeting-sap-developer-dependencies-with-2-25m-monthly-downloads-12929.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-artifacts-safe-from-npm-supply-chain-attack-targeting-sap-developer-dependencies>)

Published: 2026-04-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [npm](<https://devfeed.tech/topics/npm.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Bun](<https://devfeed.tech/topics/bun.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>)

Tags: [bun](<https://devfeed.tech/tags/bun.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [github](<https://devfeed.tech/tags/github.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [npm-worm](<https://devfeed.tech/tags/npm-worm.md>), [sap](<https://devfeed.tech/tags/sap.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

A Shai-Hulud-style npm supply-chain attack compromised four SAP Cloud Application Programming Model dependencies with more than 2.25 million combined monthly downloads. The malicious packages used a preinstall hook to download Bun and harvest GitHub tokens, npm tokens, and other developer secrets. Chainguard customers were protected because Chainguard Libraries for JavaScript does not build or serve packages containing install-time scripts, and Chainguard Factory terminated rebuilds when it detected the hook.

### Source excerpt

New npm worm targets 2.25M-download packages. Chainguard customers stayed protected by blocking install-time scripts and malicious dependencies.

## Chainguard customers safe from new npm worm and xinference supply chain attack

DevFeed: [Chainguard customers safe from new npm worm and xinference supply chain attack](<https://devfeed.tech/articles/chainguard-customers-safe-from-new-npm-worm-and-xinference-supply-chain-attack-12939.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-customers-safe-from-new-npm-worm-and-xinference-supply-chain-attack>)

Published: 2026-04-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Library](<https://devfeed.tech/topics/library.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-malware](<https://devfeed.tech/tags/chainguard-malware.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [github](<https://devfeed.tech/tags/github.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [npm-worm](<https://devfeed.tech/tags/npm-worm.md>), [packages](<https://devfeed.tech/tags/packages.md>), [pypi-malware](<https://devfeed.tech/tags/pypi-malware.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [worm](<https://devfeed.tech/tags/worm.md>), [xinference](<https://devfeed.tech/tags/xinference.md>)

### AI overview

The article reports npm and PyPI malware attacks affecting 25 packages with more than 60,000 combined monthly downloads. It explains that Chainguard customers were protected because Chainguard builds from verifiable source code and rejects packages that rely on install-time scripts.

### Source excerpt

New npm and PyPI malware hit many popular packages. Chainguard customers stayed protected by blocking install scripts and rebuilding only verified source code.

## Mitigating malware in the npm ecosystem with Chainguard Libraries

DevFeed: [Mitigating malware in the npm ecosystem with Chainguard Libraries](<https://devfeed.tech/articles/mitigating-malware-in-the-npm-ecosystem-with-chainguard-libraries-13162.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mitigating-malware-in-the-npm-ecosystem-with-chainguard-libraries>)

Published: 2025-10-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-ecosystem](<https://devfeed.tech/tags/chainguard-ecosystem.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-javascript](<https://devfeed.tech/tags/chainguard-libraries-for-javascript.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [npm-package-attack](<https://devfeed.tech/tags/npm-package-attack.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

The article presents research on using Chainguard Libraries for JavaScript to mitigate malware in the npm ecosystem. By requiring attributable source code and validating source-to-artifact integrity through a build-from-source pipeline, the study found that approximately 99% of 8,783 known malicious npm packages would have been prevented from publication, while approximately 99.7% were blocked for users relying on Chainguard Libraries as their sole source of npm dependencies.

### Source excerpt

In a recent analysis, Chainguard Libraries for JavaScript prevented over 99% of malicious npm packages published to the npm registry.