@seclink: Nationwide emergency response today — an open-source frontend library suffered a supply chain attack; any project using it may be infected with a worm. Urgent checks and upgrades needed.
Summary
Nationwide emergency response today because AntV, an open-source frontend library by Ant Group, was hit by a supply chain attack and implanted with a worm. Users need to urgently check and upgrade.
View Cached Full Text
Cached at: 05/19/26, 10:52 PM
Today, the entire country is in emergency response mode.
An open-source frontend software has been hit by a supply chain attack.
Anyone using it could be infected by a worm — check and upgrade immediately.
Y11 (@seclink):
Plain-language security alert (2026-05-19)This is a new large-scale wave of attack by the Mini Shai-Hulud worm, which previously targeted open-source projects like TanStack and SAP. Today (2026-05-19), it has set its sights on AntV, the frontend visualization library from Ant Group.
What happened?
The account atool, which maintains a large number of AntV-related npm packages, was compromised by hackers.
The attackers, within 20
Similar Articles
@AYi_AInotes: Damn, Theo’s warning today gave me chills. He said, hope you understand, this is only going to get worse, because the ongoing Mini Shai-Hulud supply chain attack has already spread from TanStack to UiPath, Mistral AI related packages, totaling 205 compromised artifacts...
This article warns about the ongoing Mini Shai-Hulud supply chain attack, which has spread from TanStack to UiPath, Mistral AI, etc., with a total of 205 artifacts poisoned. Attackers used CI/CD cache poisoning; malicious packages have legitimate signatures and provenance, rendering traditional security measures ineffective. AI has accelerated the attack speed, and developers' AI tools have become parasitic targets.
@altryne: PSA: If you are un-aware of the latest supply-chain attacks, or aware but complacent and didn't do anything, especially…
A PSA about a series of supply-chain attacks targeting AI developer tools (Hermes, OpenClaw) via npm and PyPI, specifically the 'Mini-Shai Hulud' worm that self-replicates and steals credentials, API keys, and browser sessions. The post advises sandboxed execution and restricting package age to mitigate risks.
@seclink: Share
This post shares a GitHub repository, featuring a curated set of security vulnerability samples and benchmarks, to evaluate the capabilities of static analysis tools and large models in vulnerability mining and secure code generation, covering multiple languages and the latest research findings.
@CycleDecoded: Many folks on X who are into price-drop monitoring, ticket grabbing, and deal hunting have been quietly using this tool. This killer GitHub project with 32.6k stars http://changedetection.io is basically a "global webpage watch plugin". Whether it's a price cut, stock replenishment, a silent webpage patch, ...
Introducing changedetection.io, an open-source webpage change monitoring tool that supports AI summaries, visual selection of monitored areas, multiple notification channels, and Docker private deployment.
@yhslgg: https://x.com/yhslgg/status/2072243790044442961
This article categorizes 14 web scraping tools into five groups: AI new paradigms, engineering-grade frameworks, browser automation, China-specific platforms, and modern lightweight tools, accompanied by real-world cases and selection recommendations.