Mini Shai-Hulud Returns: 600+Malicious npm Packages Fake Sigstore Badges in AntV Ecosystem Attack
Blog post from Endor Labs
Endor Labs discovered a significant malware campaign affecting the npm ecosystem on May 19, 2026, identifying 42 initial malicious packages, which later expanded to 633, including many dormant and widely-used packages like jest-canvas-mock and size-sensor. The campaign, propagating swiftly across the AntV ecosystem, utilized a novel method of Sigstore provenance forgery, making malicious packages appear legitimate by embedding a payload that generates valid Sigstore attestations. Attackers targeted dormant accounts, exploiting their inactivity to compromise them with minimal detection risk, and used two types of delivery mechanisms: phantom commit droppers and embedded payloads. The attack also involved credential harvesting and persistence mechanisms, with a primary exfiltration channel disguised as legitimate traffic. The breadth of the compromise suggests the use of a single stolen npm token for the AntV organization, while the worm's ability to produce valid provenance without authorization highlights a need for defensive strategies that do not rely solely on provenance verification.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 5 | 2,324 | 403 | 114 | +18% |
| MCP | 2 | 7,755 | 814 | 203 | -3% |
| AI Coding Assistant | 1 | 1,996 | 587 | 182 | +13% |
| Kubernetes | 1 | 2,019 | 384 | 116 | -16% |
| Observability | 1 | 3,670 | 768 | 196 | -25% |
| OpenClaw | 1 | 381 | 67 | 27 | -61% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.