A major npm supply chain attack on May 19 compromised 317 packages across 637 malicious versions in just 22 minutes by hijacking a high-privilege maintainer account. The attack targeted Alibaba's AntV data visualization namespace, affecting popular packages like size-sensor (4.2M downloads/month) and echarts-for-react (3.8M). The Mini-Shai-Hulud worm deployed by group TeamPCP steals npm/GitHub tokens, credentials from 130 file paths including cloud platforms, Kubernetes, Docker, SSH keys, and Bitcoin wallets. It also attempts to modify Claude Code's settings.json for persistence. This is the third escalating wave of npm attacks in 2025, following SAP and TanStack incidents. Developers are advised to audit dependencies, rotate credentials, check CI/CD environments for compromise, and move to verified safe package versions.