
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
Microsoft has identified an active supply chain attack targeting the @antv node package manager (npm) package ecosystem. A threat actor compromised an @antv maintainer account and published malicious versions of widely used data-visualization packages, resulting


