According to Slowmist, on May 20, multiple high-frequency npm packages including AntV and Echarts-for-react, as well as Python SDK durabletask, were compromised in a Mini Shai-Hulud supply chain attack.
Slowmist recommends immediately rotating all exposed GitHub, npm, PyPI, and cloud credentials; replacing affected packages with verified secure versions or freezing dependency versions; isolating potentially compromised systems and reviewing for credential theft or lateral movement; and applying security patches in CI/CD pipelines while reviewing post-intrusion artifacts.