Supply Chain Worm Alert: “Mini Shai-Hulud” Hits Node Ecosystem, Steals CI/CD Secrets at Scale
Popular @antv npm packages were compromised to inject malicious code that steals CI/CD credentials, environment variables, and Git tokens from developer systems. Over 1.5 million weekly downloads put thousands of organizations at risk of supply chain attacks targeting their build pipelines and deplo