Large-Scale Supply Chain Attack Hits 637 npm Packages, GitHub and Grafana Potentially Affected

GateNews

According to Slow Mist threat intelligence, a large-scale supply chain attack known as 'Mini Shai-Hulud' recently compromised the npm account atool, deploying 637 malicious versions across 317 packages within 22 minutes. High-frequency packages including AntV and Echarts-for-react were affected, alongside Python SDK durabletask versions 1.4.1, 1.4.2, and 1.4.3, which were falsely published under the guise of official Microsoft releases.

The attack enabled unauthorized access to credentials, internal repositories, and sensitive cloud infrastructure, with potential lateral movement to developer machines and CI/CD pipelines. GitHub token leaks and Grafana Labs' recent ransomware incident are likely connected to this campaign. Slow Mist recommends immediately rotating exposed credentials, replacing affected packages, isolating potentially compromised systems, and implementing strict dependency review policies.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments