{
  "Event": {
    "analysis": "1",
    "date": "2026-05-20",
    "extends_uuid": "",
    "info": "[Threat Intel] Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft",
    "protected": false,
    "publish_timestamp": "1780196740",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780196739",
    "uuid": "ce69c87f-4292-4c48-9907-0aea83122aed",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#96f4f6",
        "local": false,
        "name": "misp-galaxy:producer=\"Microsoft\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#bb2745",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Standard Encoding - T1132.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#95f9b9",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Sudo and Sudo Caching - T1548.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#cad64d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Groups - T1069.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#201172",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Dependencies and Development Tools - T1195.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#e7d11f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#461928",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Indicator Blocking - T1562.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7ffc24",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Additional Cloud Credentials - T1098.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#12d28f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Account - T1087.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#71ecdb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Account Manipulation - T1098\"",
        "relationship_type": ""
      },
      {
        "colour": "#6d779a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exploitation for Privilege Escalation - T1068\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#37c019",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Shai-Hulud\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#220082",
        "local": false,
        "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418835",
        "to_ids": false,
        "type": "link",
        "uuid": "e6ef24bc-9158-46c1-99a7-c55ea4611a70",
        "value": "https://www.microsoft.com/en-us/security/blog/2026/05/20/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418835",
        "to_ids": false,
        "type": "text",
        "uuid": "a5f5a085-4383-4929-8d37-56bfc05fbb65",
        "value": "Microsoft identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv maintainer account and published malicious versions of widely used data-visualization packages, affecting libraries like echarts-for-react with over 1 million weekly downloads. The attack propagates through dependency chains into CI/CD pipelines and cloud workloads. A 499 KB obfuscated JavaScript payload executes silently during npm install, specifically designed to steal credentials from GitHub Actions environments. Key capabilities include multi-platform credential theft (GitHub, AWS, HashiCorp Vault, npm, Kubernetes, 1Password), GitHub Action Runner process memory scraping, privilege escalation, dual-channel data exfiltration, and SLSA provenance forgery. The payload targets CI/CD environments deliberately, with over 2,200 compromised repositories observed. GitHub responded by removing 640 malicious packages and invalidating 61,274 npm tokens."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418835",
        "to_ids": false,
        "type": "text",
        "uuid": "c1ebd64c-52a1-40c7-ba0b-39630a31e38c",
        "value": "Name: Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft\nAuthor: AlienVault\nAdversary: \nTags: [\"supply chain attack\", \"npm\", \"credential theft\", \"obfuscation\", \"privilege escalation\", \"github actions\", \"ci/cd\", \"data exfiltration\"]\nTgtd countries: []\nMlwr families: []\nAttack_ids: [\"T1132.001\", \"T1059.007\", \"T1548.003\", \"T1069.003\", \"T1195.001\", \"T1036.005\", \"T1140\", \"T1552.004\", \"T1562.006\", \"T1552.001\", \"T1098.001\", \"T1087.004\", \"T1098\", \"T1068\", \"T1027\", \"T1195.002\", \"T1567.002\", \"T1071.001\", \"T1105\", \"T1078.004\"]\nIndustries: []"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780196233",
        "to_ids": true,
        "type": "hostname",
        "uuid": "4dce28a5-7048-4b66-bd4d-7e4911b989ed",
        "value": "t.m-kosche.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780196254",
        "to_ids": true,
        "type": "url",
        "uuid": "2f2b696e-d0a0-4949-9998-240254630ab8",
        "value": "http://t.m-kosche.com:443",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:30/05/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150020",
        "to_ids": true,
        "type": "sha256",
        "uuid": "bbae8503-b06e-407c-93fb-b2390e590afc",
        "value": "a8269c01069452afb8a54de904e6419578d155fdbdb9e566bab8576a4266b61e",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780196275",
        "uuid": "c0ccee49-3c75-4e60-83c4-97faee94b6d5",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "Malicious backdoor Python script",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780196275",
            "to_ids": true,
            "type": "md5",
            "uuid": "a41fa9d4-fa1f-4a2e-9504-a966418b39c4",
            "value": "b06b126b9e26af03a7ef2f8b8e90d446",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Malicious backdoor Python script",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780150018",
            "to_ids": true,
            "type": "sha1",
            "uuid": "1e448fa4-08f9-47ba-81fe-f7eea33655de",
            "value": "783b4019fc5b942a29846132d28441c8fc31bed8",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Malicious backdoor Python script",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780150018",
            "to_ids": true,
            "type": "sha256",
            "uuid": "5128aa57-21e8-4b94-a4f3-e87810cf6afc",
            "value": "fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780149390",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "c022d35c-f02a-427b-a910-b9d1123e4dd7",
            "value": "96:L2V79jNRLZ1e/MJUJga1wXn3J3WSOGb6eYPd3ZUPtW6i:La9LZ4/MJxKM3RW4bzGxZ0tvi"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780149390",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "5ead8a38-5146-48bc-8878-da2ff058b4f6",
            "value": "8081"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780149390",
            "to_ids": true,
            "type": "filename",
            "uuid": "32e67500-dff3-4aa1-b388-708dbb27a859",
            "value": "cat.py"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  30/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780149390",
            "to_ids": false,
            "type": "text",
            "uuid": "78da99fa-f2c8-4d0c-b368-428f78137949",
            "value": "Malicious backdoor Python script\r\nType Description: Python\nMicrosoft: Backdoor:Python/Vigorf.A\nVT Total Detection:32/62\nFirst Submission:2026-05-21T01:29:11.000000+00:00\nLast Submission:2026-05-29T08:48:32.000000+00:00"
          }
        ]
      },
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780196296",
        "uuid": "da4019b6-604e-45db-8158-49e2d6ed1973",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "Malicious payload JavaScript file",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780196296",
            "to_ids": true,
            "type": "md5",
            "uuid": "9554d695-b096-46fa-a6ac-cd89cf810cdf",
            "value": "8f8f24b6bc727e18295feaad45d17b44",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Malicious payload JavaScript file",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780150019",
            "to_ids": true,
            "type": "sha1",
            "uuid": "0b8ae6a4-d21b-40b9-89a4-021fd0355bfc",
            "value": "19b62ae4f76273645e36a60e7b7d23c05c16b395",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Malicious payload JavaScript file",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780150019",
            "to_ids": true,
            "type": "sha256",
            "uuid": "582b3e18-cae5-46c6-a3e4-fb670813c13c",
            "value": "a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780149411",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "235ba76c-9583-41df-b8f4-07f4d6877d6b",
            "value": "12288:U8eTfcQoIuTtfrEbWww3LhtCGhYarwlnO9KDq:U8eTEmuTtfobWhjNhYarwl2K2"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780149411",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "f3f0cb75-36cf-4ce9-bdec-7b865cf1a334",
            "value": "498431"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780149411",
            "to_ids": true,
            "type": "filename",
            "uuid": "89deb8dc-9eef-449b-ba0b-2e8bc9e10569",
            "value": "index.js"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  30/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780149411",
            "to_ids": false,
            "type": "text",
            "uuid": "1268864a-028a-4bff-9835-eae2cede0062",
            "value": "Malicious payload JavaScript file\r\nType Description: JavaScript\nMicrosoft: Trojan:AIGen/NPMStealer.B\nVT Total Detection:30/61\nFirst Submission:2026-05-19T03:13:56.000000+00:00\nLast Submission:2026-05-21T17:05:58.000000+00:00"
          }
        ]
      }
    ]
  }
}