{
  "Event": {
    "analysis": "1",
    "date": "2026-05-19",
    "extends_uuid": "",
    "info": "[Threat Intel] Active Supply Chain Attack Compromises Packages on npm",
    "protected": false,
    "publish_timestamp": "1780138990",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780138990",
    "uuid": "05e5980c-095e-4789-a521-73f3eb7e7b31",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#0ee843",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Instance Metadata API - T1552.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#56c932",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Symmetric Cryptography - T1573.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#f5a258",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Native API - T1106\"",
        "relationship_type": ""
      },
      {
        "colour": "#e00500",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Access Tools - T1219\"",
        "relationship_type": ""
      },
      {
        "colour": "#e7d11f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration to Code Repository - T1567.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7628f7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Unix Shell - T1059.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#30cc3b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#a0cbec",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#37c019",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#3b4369",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Container API - T1552.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:producer=\"37ebf9d7-5e9a-466f-a42c-6e60313db868\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Shai-Hulud\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779246007",
        "to_ids": false,
        "type": "link",
        "uuid": "9283c857-afb3-46ab-9ed7-951271a0d7d8",
        "value": "https://socket.dev/blog/antv-packages-compromised"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779246007",
        "to_ids": false,
        "type": "text",
        "uuid": "ba3b13c9-6ffd-409d-b89a-0c08f38e025c",
        "value": "An active npm supply chain attack has compromised packages in the @antv ecosystem, affecting the maintainer account 'atool'. The attack is part of the Mini Shai-Hulud campaign, involving 639 compromised package versions across 323 unique packages. Notable affected packages include echarts-for-react with 1.1 million weekly downloads, and widely-used @antv packages for data visualization. The malware uses obfuscated install-time payloads that harvest developer credentials, GitHub tokens, npm tokens, AWS credentials, and other secrets from development and CI/CD environments. Stolen data is encrypted with AES-256-GCM and exfiltrated to a command-and-control server, with GitHub repositories used as fallback channels. The malware contains worm-like functionality to republish compromised packages and propagate through the npm ecosystem."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779246007",
        "to_ids": false,
        "type": "text",
        "uuid": "f0258a9e-7576-4add-8c2b-ddc1cbe640cd",
        "value": "Name: Active Supply Chain Attack Compromises Packages on npm\nAuthor: AlienVault\nAdversary: \nTags: [\"mini shai-hulud\", \"credential theft\", \"@antv packages\", \"supply chain attack\", \"npm\", \"echarts-for-react\", \"github exfiltration\", \"ci/cd compromise\"]\nTgtd countries: []\nMlwr families: [\"Mini Shai-Hulud\"]\nAttack_ids: [\"T1059.007\", \"T1552.005\", \"T1573.001\", \"T1106\", \"T1219\", \"T1552.004\", \"T1552.001\", \"T1567.001\", \"T1059.004\", \"T1027\", \"T1195.002\", \"T1070.004\", \"T1071.001\", \"T1543.002\", \"T1105\", \"T1078.004\", \"T1552.007\"]\nIndustries: [\"Technology\"]"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135358",
        "to_ids": true,
        "type": "hostname",
        "uuid": "86aea7ce-b8f7-4aa8-9b35-296a07108771",
        "value": "t.m-kosche.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:30/05/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780131008",
        "to_ids": true,
        "type": "sha1",
        "uuid": "a280ab27-e864-438f-ba5e-87c1987ad3ee",
        "value": "1916faa365f2788b6e193514872d51a242876569",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135379",
        "to_ids": true,
        "type": "url",
        "uuid": "50ff1734-daba-4667-bcf5-903120e50de7",
        "value": "https://t.m-kosche.com:443/api/public/otel/v1/traces",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "legitimate npm and Sigstore services. They are not threat actor-controlled infrastructure and should not be blocked by default. They are included as detection opportunities",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135400",
        "to_ids": true,
        "type": "url",
        "uuid": "58d493dc-a259-462b-901e-0775892cd842",
        "value": "https://registry.npmjs.org/-/npm/v1/tokens",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "legitimate npm and Sigstore services. They are not threat actor-controlled infrastructure and should not be blocked by default. They are included as detection opportunities",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135421",
        "to_ids": true,
        "type": "url",
        "uuid": "09db7749-6d5b-4680-95b7-0d00965f0236",
        "value": "https://registry.npmjs.org/-/whoami",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "legitimate npm and Sigstore services. They are not threat actor-controlled infrastructure and should not be blocked by default. They are included as detection opportunities",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135442",
        "to_ids": true,
        "type": "url",
        "uuid": "f635e903-0d69-463f-902b-8c88b64026f2",
        "value": "https://registry.npmjs.org/-/v1/search?text=maintainer:",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "legitimate npm and Sigstore services. They are not threat actor-controlled infrastructure and should not be blocked by default. They are included as detection opportunities",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135464",
        "to_ids": true,
        "type": "url",
        "uuid": "0199ef3f-d3bf-4130-b56f-a6e6d20b0fc8",
        "value": "https://fulcio.sigstore.dev/api/v2/signingCert",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "legitimate npm and Sigstore services. They are not threat actor-controlled infrastructure and should not be blocked by default. They are included as detection opportunities",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780135485",
        "to_ids": true,
        "type": "url",
        "uuid": "4d842439-d56c-42ee-9b34-fe6c6086ec85",
        "value": "https://rekor.sigstore.dev/api/v1/log/entries",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}