The Hacker News
Researchers have identified a software supply chain attack that has compromised several npm packages linked to the @antv ecosystem. The attack stems from a compromised maintainer account for the npm package 'atool.' Notably, this includes 'echarts-for-react,' a popular React wrapper for Apache ECharts, which has around 1.1 million weekly downloads. This incident is part of a broader campaign known as Mini Shai-Hulud and raises concerns about the security of widely used development tools. Developers and organizations using these packages should check their dependencies for any malicious changes and take appropriate actions to secure their software supply chains.