Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise

https://image.theregister.com/5242669.jpg?imageId=5242669&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Popular JavaScript modules including size-sensor and echarts-for-react hit as hijacked account closed GitHub warnings

An npm account compromise infected 314 npm packages with malware, including size-sensor, echarts-for-react, timeago.js,and packages scoped to @antv, in a 22-minute burst of activity in the early hours of Tuesday morning.

The most popular impacted package is size-sensor, downloaded4.2 million times per month, followed by echarts-for-react (3.8 million), @antv/scale(2.2 million) and timeago.js (1.15 million).

The compromised account, i@hust.cc, belongs to a developer based inHangzhou, China. Security researcher Nicholas Carlini reported the malware on GitHub, and the the hust.cc account closed the issues and marked them as "fixed" within an hour. This means the malware report on thisand other repositories is hidden unless a developer looks for closed issues.

Some malicious package versions have been deprecated on npm with the message "thisversion was published in error, please use the latest version instead,"while others have been removed.

...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more

https://www.eu-startups.com/wp-content/uploads/2026/05/Untitled-design-2026-05-19T165310.544.jpg

Berlin-based bunch, an AI-native platform for managers and institutional investors to manage the entire fund lifecycle, raised a €30.1M Series B led by Portage

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. Protecting your Cloud Applications Data — Backing up Office 365, Google Workspace, Dropbox & Salesforce data