---
title: "AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks"
url: https://daily.dev/posts/antv-data-visualization-tool-the-latest-to-be-hit-by-ongoing-npm-supply-chain-attacks-qb3fstdma
source_url: https://www.infoworld.com/article/4173277/antv-data-visualization-tool-the-latest-to-be-hit-by-ongoing-npm-supply-chain-attacks.html
type: article
source: "InfoWorld"
published: 2026-05-19T19:11:41.966Z
updated: 2026-05-19T19:12:13.539Z
tags: ["security", "cicd", "malware", "npm"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks

**[InfoWorld](https://daily.dev/sources/infoworld)** · 4 min read · 0 upvotes · 0 comments

## Summary

A major npm supply chain attack on May 19 compromised 317 packages across 637 malicious versions in just 22 minutes by hijacking a high-privilege maintainer account. The attack targeted Alibaba's AntV data visualization namespace, affecting popular packages like size-sensor (4.2M downloads/month) and echarts-for-react (3.8M). The Mini-Shai-Hulud worm deployed by group TeamPCP steals npm/GitHub tokens, credentials from 130 file paths including cloud platforms, Kubernetes, Docker, SSH keys, and Bitcoin wallets. It also attempts to modify Claude Code's settings.json for persistence. This is the third escalating wave of npm attacks in 2025, following SAP and TanStack incidents. Developers are advised to audit dependencies, rotate credentials, check CI/CD environments for compromise, and move to verified safe package versions.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.infoworld.com/article/4173277/antv-data-visualization-tool-the-latest-to-be-hit-by-ongoing-npm-supply-chain-attacks.html>

## Similar posts on daily.dev

- [Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem](https://daily.dev/posts/shai-hulud-here-we-go-again-mass-npm-supply-chain-attack-hits-the-antv-ecosystem-nq51smsqn) · StepSecurity · 1 upvotes · 0 comments
- [Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages](https://daily.dev/posts/mini-shai-hulud-strikes-again-npm-worm-compromises-hundreds-of-antv-packages-gsrjcznzd) · Aikido Security · 0 upvotes · 0 comments
- [Mini Shai-Hulud Hits AntV: 300\+ Malicious npm Packages Published via Compromised Maintainer Account](https://daily.dev/posts/mini-shai-hulud-hits-antv-300-malicious-npm-packages-published-via-compromised-maintainer-account-kixznqqun) · Snyk · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cicd](https://daily.dev/tags/cicd), [#malware](https://daily.dev/tags/malware), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/antv-data-visualization-tool-the-latest-to-be-hit-by-ongoing-npm-supply-chain-attacks-qb3fstdma)
