Mini Shai-Hulud Malware Infects Popular npm Packages Including echarts-for-react, 1.1M Weekly Downloads Affected

GateNews
According to PANews on May 20, open-source packages including echarts-for-react (1.1 million weekly downloads) and other high-frequency components were infected by the 'Mini Shai-Hulud' malware worm. The infected version 3.2.7 was flagged as malware within 19 minutes of release, with the package's supply chain security score dropping to zero. The attack stemmed from a compromised developer account (username: atool), which attackers used to inject obfuscated malicious code into multiple dependencies.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments