FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity

NPM malware attack targets AntV tool

Illustration of a broken chain link representing a software supply chain attack on the npm package registry, impacting a data visualization tool.

TL;DR: The npm registry has experienced another malware attack, this time affecting the AntV data visualization tool. The incident occurred after an attacker compromised the credentials of a maintainer for the popular `timeago.js` library, highlighting ongoing risks in the open-source software supply chain.

By Neeraj Dhiman·May 21, 2026·1 min read·updated 1d ago
Source

Key facts

Category
Cybersecurity
Impact
Low
Published
May 21, 2026
Source
CSO Online

Full summary

The AntV data visualization tool was targeted in a new npm supply chain attack after a maintainer's account was compromised.

The npm open-source registry has been hit by another supply chain attack, this time impacting users of the AntV data visualization tool. The incident stemmed from the compromised credentials of a maintainer for the popular `timeago.js` JavaScript library. According to security analysts, an attacker gained control of the `atool` npm account, which is responsible for publishing `timeago.js`. This attack vector is more conventional than the recent high-profile incident involving TanStack, which exploited a complex GitHub Actions vulnerability. Instead, this attack relied on gaining direct access to a high-value maintainer account.

This event underscores the persistent threat of supply chain attacks within the software development lifecycle. By targeting a widely-used dependency like `timeago.js`, attackers can inject malicious code that propagates to countless downstream projects and applications that use the AntV tool. The compromise highlights how a single point of failure—in this case, a maintainer's account—can have far-reaching consequences for developers, IT teams, and businesses that rely on the integrity of the open-source ecosystem. It serves as a critical reminder that even trusted packages can become vectors for malware.

The rapid succession of attacks on the npm registry emphasizes the need for heightened security measures across the board. For package maintainers, this means enforcing multi-factor authentication and practicing strong credential hygiene. For developers and organizations consuming these packages, it is crucial to implement dependency scanning tools to quickly identify and respond to compromised components. Continuous monitoring is becoming an essential practice to mitigate these ongoing threats.

Why it matters

This attack highlights the ongoing risk of software supply chain vulnerabilities, where compromising a single popular package can impact thousands of downstream applications and companies.

Business impact

Companies using the AntV data visualization tool or the `timeago.js` library may have inadvertently installed malicious code, exposing them to potential data theft or system compromise. This requires immediate investigation and remediation, potentially causing operational disruption.

⚡ Action needed

Users of the AntV data visualization tool and the `timeago.js` library should immediately review their dependencies for any malicious versions and update to a secure release. It is critical to audit systems for signs of compromise.

Action checklist

  1. 1Identify all projects using AntV or `timeago.js`.
  2. 2Check for and remove any compromised versions of the packages.
  3. 3Update to the latest secure versions of the affected libraries.
  4. 4Scan systems and logs for any signs of malicious activity.
  5. 5Review and enforce multi-factor authentication for all developer accounts.

Tags

#security#malware#npm#supply chain attack#javascript#antv

Related on Notifire

  • ResearchKubernetes security
  • ResearchSoftware supply-chain security
  • ResearchCritical CVEs of 2026

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related stories

Primary source: CSO Online

Part of our research on

  • Software supply-chain security →
  • Critical CVEs of 2026 →

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube