@antv/g-image-exporter
MAL-2026-3837
npmmalware5/19/2026
Description
Malicious code in @antv/g-image-exporter (npm)
Indicators of Compromise
SHA256 Hashes (2)
3a4cd69e10581219a31786a2eabe6e9e3d4f20e3e4fb49c1a43f520416a819c5
847ef6b381d410bf176f7414a6f0fbbcf46a5f39b6d9011e126b279bd2d781df
References (5)
https://github.com/advisories/GHSA-43gp-g42f-r82gOSVhttps://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/OSVhttps://socket.dev/blog/antv-packages-compromisedOSVhttps://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/OSVhttps://opensourcemalware.com/blog/teampcp-compromises-npm-maintainer-with-over-540-packagesOSV
Details
Ecosystemnpm
Attack Typemalware
Published5/19/2026
Aliases
GHSA-43gp-g42f-r82g
Quick Actions