---
title: "Compromised atool npm Account Delivers CI/CD Credential Stealer Across 24 Packages (echarts-for-react package, timeago.js)"
url: https://daily.dev/posts/compromised-atool-npm-account-delivers-ci-cd-credential-stealer-across-24-packages-echarts-for-reac-mrogwbggw
source_url: https://www.stepsecurity.io/blog/compromised-atool-npm-account-delivers-ci-cd-credential-stealer-across-24-packages-echarts-for-react-package-timeago-js
type: article
source: "StepSecurity"
published: 2026-05-19T04:08:25.359Z
updated: 2026-05-19T04:08:42.132Z
tags: ["security", "cicd", "malware", "npm"]
reading_time: 1
upvotes: 5
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Compromised atool npm Account Delivers CI/CD Credential Stealer Across 24 Packages (echarts-for-react package, timeago.js)

**[StepSecurity](https://daily.dev/sources/stepsecurity)** · 1 min read · 5 upvotes · 0 comments

## Summary

The npm account 'atool' (associated with GitHub user hustcc) was compromised, leading to malicious releases across 24 packages in a 10-minute window on May 19, 2026. The attacker targeted high-download packages including timeago.js (1.5M+ weekly downloads) and the AntV visualization ecosystem (packages like @antv/g6, @antv/g2, @antv/l7). The malicious code functions as a CI/CD credential stealer, targeting environments like GitHub Actions, GitLab CI, and Kubernetes-hosted pipelines that hold elevated cloud credentials. Affected packages are widely used in data engineering pipelines, financial dashboards, and enterprise React/Vue/Angular front-end builds.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.stepsecurity.io/blog/compromised-atool-npm-account-delivers-ci-cd-credential-stealer-across-24-packages-echarts-for-react-package-timeago-js>

## Similar posts on daily.dev

- [Shai-Hulud: Here We Go Again. Mass npm Supply Chain Attack Hits the AntV Ecosystem](https://daily.dev/posts/shai-hulud-here-we-go-again-mass-npm-supply-chain-attack-hits-the-antv-ecosystem-nq51smsqn) · StepSecurity · 1 upvotes · 0 comments
- [Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised](https://daily.dev/posts/mini-shai-hulud-strikes-again-317-npm-packages-compromised-u2ptexbxr) · Hacker News · 2 upvotes · 0 comments
- [AntV data visualization tool the latest to be hit by ongoing npm supply chain attacks](https://daily.dev/posts/antv-data-visualization-tool-the-latest-to-be-hit-by-ongoing-npm-supply-chain-attacks-qb3fstdma) · InfoWorld · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cicd](https://daily.dev/tags/cicd), [#malware](https://daily.dev/tags/malware), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/compromised-atool-npm-account-delivers-ci-cd-credential-stealer-across-24-packages-echarts-for-reac-mrogwbggw)
