critical severityConfidence highHistorical record

Mini Shai-Hulud @antv npm worm wave

Aikido documented a May 2026 Mini Shai-Hulud wave compromising packages in the @antv ecosystem and other npm projects, stealing credentials and planting persistence in VS Code and Claude Code configuration.

Also tracked as Mini Shai-Hulud @antv wave

First observed
May 19, 2026
Last observed
May 19, 2026
Last reviewed
Sep 2, 2026
Tracking ended
Sep 8, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

This page covers the reviewed May 19 wave, not every earlier or later Mini Shai-Hulud incident. Counts of packages, repositories, and affected credentials can change as investigations progress.

  • Removing a dependency alone is insufficient when persistence or credentials may already have been modified; follow the incident source and rotate exposed secrets.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

Not covered, or partially covered

  • partial

    Eligible dependency-install actions can be policy-controlled, but stolen publishing credentials and already-executed worm propagation require registry and endpoint remediation.

  • partial

    Claude Code is a supported harness, but Guard does not claim that every out-of-band modification to Claude configuration is automatically intercepted.

  • Recipe available

    Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.

    Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.

  • Recipe available

    Review unexpected changes to agent and editor instruction/configuration files before relying on the affected workspace.

    Current Guard coverage is harness- and event-specific. Configuration changes made outside an observed surface may require separate repository or endpoint controls.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. First observed

    Mini Shai-Hulud @antv npm worm wave was first observed in the reviewed source material.

  2. Disclosure

    The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 1979.5 hours from reviewed disclosure timestamp to HOL publication; 12-hour critical target; historical backfill outside target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • @antv affected package setnpmpackage
  • .claude/settings.json persistence pathClaude Codeconfig

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Research.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-MINISHAI26