@seclink: Nationwide emergency response today — an open-source frontend library suffered a supply chain attack; any project using it may be infected with a worm. Urgent checks and upgrades needed.

X AI KOLs Following News

Summary

Nationwide emergency response today because AntV, an open-source frontend library by Ant Group, was hit by a supply chain attack and implanted with a worm. Users need to urgently check and upgrade.

Nationwide emergency response today — an open-source frontend library suffered a supply chain attack, any project using it may be infected with a worm. Urgent checks and upgrades needed.
Original Article
View Cached Full Text

Cached at: 05/19/26, 10:52 PM

Today, the entire country is in emergency response mode.
An open-source frontend software has been hit by a supply chain attack.
Anyone using it could be infected by a worm — check and upgrade immediately.

Y11 (@seclink):
Plain-language security alert (2026-05-19)

This is a new large-scale wave of attack by the Mini Shai-Hulud worm, which previously targeted open-source projects like TanStack and SAP. Today (2026-05-19), it has set its sights on AntV, the frontend visualization library from Ant Group.
What happened?
The account atool, which maintains a large number of AntV-related npm packages, was compromised by hackers.
The attackers, within 20

Similar Articles

@AYi_AInotes: Damn, Theo’s warning today gave me chills. He said, hope you understand, this is only going to get worse, because the ongoing Mini Shai-Hulud supply chain attack has already spread from TanStack to UiPath, Mistral AI related packages, totaling 205 compromised artifacts...

X AI KOLs Timeline

This article warns about the ongoing Mini Shai-Hulud supply chain attack, which has spread from TanStack to UiPath, Mistral AI, etc., with a total of 205 artifacts poisoned. Attackers used CI/CD cache poisoning; malicious packages have legitimate signatures and provenance, rendering traditional security measures ineffective. AI has accelerated the attack speed, and developers' AI tools have become parasitic targets.

@seclink: Share

X AI KOLs Timeline

This post shares a GitHub repository, featuring a curated set of security vulnerability samples and benchmarks, to evaluate the capabilities of static analysis tools and large models in vulnerability mining and secure code generation, covering multiple languages and the latest research findings.

@CycleDecoded: Many folks on X who are into price-drop monitoring, ticket grabbing, and deal hunting have been quietly using this tool. This killer GitHub project with 32.6k stars http://changedetection.io is basically a "global webpage watch plugin". Whether it's a price cut, stock replenishment, a silent webpage patch, ...

X AI KOLs Timeline

Introducing changedetection.io, an open-source webpage change monitoring tool that supports AI summaries, visual selection of monitored areas, multiple notification channels, and Docker private deployment.

@yhslgg: https://x.com/yhslgg/status/2072243790044442961

X AI KOLs Timeline

This article categorizes 14 web scraping tools into five groups: AI new paradigms, engineering-grade frameworks, browser automation, China-specific platforms, and modern lightweight tools, accompanied by real-world cases and selection recommendations.