Sometime in late May 2026, a poisoned update slipped into the @antv family of JavaScript visualization libraries, the ...
Mini Shai-Hulud npm campaign compromises @antv packages, targeting blockchain developers' GitHub tokens, AWS keys, and CI/CD secrets in a coordinated supply chain attack.