According to Slow Mist threat intelligence, a large-scale supply chain attack known as 'Mini Shai-Hulud' recently compromised the npm account atool, deploying 637 malicious versions across 317 packages within 22 minutes. High-frequency packages including AntV and Echarts-for-react were affected, alongside Python SDK durabletask versions 1.4.1, 1.4.2, and 1.4.3, which were falsely published under the guise of official Microsoft releases.
The attack enabled unauthorized access to credentials, internal repositories, and sensitive cloud infrastructure, with potential lateral movement to developer machines and CI/CD pipelines. GitHub token leaks and Grafana Labs' recent ransomware incident are likely connected to this campaign. Slow Mist recommends immediately rotating exposed credentials, replacing affected packages, isolating potentially compromised systems, and implementing strict dependency review policies.