Mini Shai-Hulud Returns: 600+Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack
Blog post from Endor Labs
Endor Labs discovered a significant malware campaign affecting the npm ecosystem on May 19, 2026, identifying 42 initial malicious packages, which later expanded to 633, including many dormant and widely-used packages like jest-canvas-mock and size-sensor. The campaign, propagating swiftly across the AntV ecosystem, utilized a novel method of Sigstore provenance forgery, making malicious packages appear legitimate by embedding a payload that generates valid Sigstore attestations. Attackers targeted dormant accounts, exploiting their inactivity to compromise them with minimal detection risk, and used two types of delivery mechanisms: phantom commit droppers and embedded payloads. The attack also involved credential harvesting and persistence mechanisms, with a primary exfiltration channel disguised as legitimate traffic. The breadth of the compromise suggests the use of a single stolen npm token for the AntV organization, while the worm's ability to produce valid provenance without authorization highlights a need for defensive strategies that do not rely solely on provenance verification.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 5 | 2,152 | 360 | 101 | +18% |
| MCP | 2 | 7,098 | 726 | 186 | +16% |
| AI Coding Assistant | 1 | 1,798 | 527 | 167 | +21% |
| Kubernetes | 1 | 1,965 | 371 | 106 | -15% |
| Observability | 1 | 3,421 | 707 | 180 | -24% |
| OpenClaw | 1 | 329 | 55 | 25 | -47% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.