@antv/gi-assets-advance
MAL-2026-3838
npmmalware5/19/2026
Description
Malicious code in @antv/gi-assets-advance (npm)
Indicators of Compromise
SHA256 Hashes (2)
4d228bc597da3dc848598761e07005bed0d035c1ec9814525153dae7f8884291
847ef6b381d410bf176f7414a6f0fbbcf46a5f39b6d9011e126b279bd2d781df
References (5)
https://github.com/advisories/GHSA-c27c-w76m-gf2pOSVhttps://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/OSVhttps://socket.dev/blog/antv-packages-compromisedOSVhttps://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/OSVhttps://opensourcemalware.com/blog/teampcp-compromises-npm-maintainer-with-over-540-packagesOSV
Details
Ecosystemnpm
Attack Typemalware
Published5/19/2026
Aliases
GHSA-c27c-w76m-gf2p
Quick Actions