{"schemaVersion":"guard-threat-campaign/v1","id":"HGTC-2026-MINISHAI26","slug":"mini-shai-hulud-antv-npm-worm","title":"Mini Shai-Hulud @antv npm worm wave","aliases":["Mini Shai-Hulud @antv wave"],"summary":"Aikido documented a May 2026 Mini Shai-Hulud wave compromising packages in the @antv ecosystem and other npm projects, stealing credentials and planting persistence in VS Code and Claude Code configuration.","status":"published","severity":"critical","confidence":"high","uncertainty":"This page covers the reviewed May 19 wave, not every earlier or later Mini Shai-Hulud incident. Counts of packages, repositories, and affected credentials can change as investigations progress.","firstObservedAt":"2026-05-19T00:00:00.000Z","lastObservedAt":"2026-05-19T00:00:00.000Z","publishedAt":"2026-08-09T11:30:00.000Z","reviewedAt":"2026-08-09T11:20:00.000Z","expiresAt":"2026-09-08T23:59:59.000Z","reviewer":"HOL Guard Research","sources":[{"id":"source:aikido-mini-shai-hulud","label":"Aikido: Mini Shai-Hulud @antv wave","url":"https://www.aikido.dev/blog/mini-shai-hulud-antv-npm-supply-chain-attack","sourceType":"other_primary","observedAt":"2026-08-09T11:20:00.000Z"}],"artifacts":[{"id":"artifact:antv-scope","artifactClass":"package","ecosystem":"npm","name":"@antv affected package set","version":null,"defanged":true},{"id":"artifact:claude-settings","artifactClass":"config","ecosystem":"Claude Code","name":".claude/settings.json persistence path","version":null,"defanged":true}],"indicators":[],"timeline":[{"id":"timeline:first-observed","occurredAt":"2026-05-19T00:00:00.000Z","eventType":"first_observed","summary":"Mini Shai-Hulud @antv npm worm wave was first observed in the reviewed source material.","sourceIds":["source:aikido-mini-shai-hulud"]},{"id":"timeline:disclosure","occurredAt":"2026-05-19T00:00:00.000Z","eventType":"disclosure","summary":"The reviewed source published or updated its defensive analysis and remediation guidance.","sourceIds":["source:aikido-mini-shai-hulud"]}],"coverage":[{"assertionId":"coverage:stable:codex","relationship":"partial","limitation":"Eligible dependency-install actions can be policy-controlled, but stolen publishing credentials and already-executed worm propagation require registry and endpoint remediation."},{"assertionId":"coverage:stable:claude-code","relationship":"partial","limitation":"Claude Code is a supported harness, but Guard does not claim that every out-of-band modification to Claude configuration is automatically intercepted."}],"policies":[{"policyId":"policy:package-install-review","purpose":"Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.","status":"available","limitation":"Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted."},{"policyId":"policy:agent-config-integrity-review","purpose":"Review unexpected changes to agent and editor instruction/configuration files before relying on the affected workspace.","status":"available","limitation":"Current Guard coverage is harness- and event-specific. Configuration changes made outside an observed surface may require separate repository or endpoint controls."}],"limitations":["Removing a dependency alone is insufficient when persistence or credentials may already have been modified; follow the incident source and rotate exposed secrets."],"correctionHref":"/guard/security/campaigns/mini-shai-hulud-antv-npm-worm/corrections"}