News
Warning: The "mini-sandworm" worm has recently completed a large-scale infection in open-source code repositories. Developers need to be vigilant and conduct thorough checks.
en
On May 20, crypto KOL @mubeitech issued a reminder that an open-source foundational package, downloaded 1.1 million times weekly, has been flagged by systems as known malware. Its supply chain security score has dropped to zero. This is a code worm called "Mini Shai-Hulud," which has recently caused widespread infections in open-source code repositories.
The list of victims includes high-frequency components. Alibaba's data visualization suite antv had hundreds of packages implanted with malicious code. Frequently used frontend tools like echarts-for-react and timeago.js were also affected. echarts-for-react alone has 1.1 million weekly installations. The incident originated from a compromised ordinary developer account. The account named "atool" had its permissions stolen. After taking control, hackers injected obfuscated malicious code into these underlying components. Just 19 minutes after the infected version 3.2.7 was released, vulnerability scans all turned red.
SlowMist Chief Information Security Officer 23pds forwarded the post and issued a reminder for developers to conduct checks.