← WeSearch · Blindspots
Full coverage · not a ranking

Mini Shai-Halud hackers publish over 600 compromised npm packages — developers warned to be on their guard

First seen May 18, 2026, 10:34 PM · latest May 20, 2026, 8:40 AM · free · no behavioral personalization
2Articles in sample
2Distinct publishers
0Wire-service items
0High-fact publishers

2 distinct publishers, one article each in this sample.

Ownership mix: Other: 2

What happened
A compromised npm maintainer account published 631 malicious versions across 314 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

2 publishers · 2 articles · switch to 1-minute for disagreement and framing.

What happened

A compromised npm maintainer account published 631 malicious versions across 314 packages including size-sensor, echarts-for-react, timeago.js, and hundreds of @antv scoped packages, affecting 15M+ monthly downloads.

Why the coverage differs

AI-assisted comparison · labeled · generated just generated or not yet stored · not a verdict

The Shai-Hulud malware campaign expanded to compromise 314 npm packages, including size-sensor and echarts-for-react, after a maintainer account was hijacked. This incident resulted in 631 malicious versions being published, impacting over 15 million monthly downloads. Both outlets confirm the scale of the breach and the specific packages involved.

Coverage diverges primarily in technical granularity versus general advisory tone. SafeDep provides a precise inventory of affected libraries and quantifies the exact number of malicious versions, catering to developers needing immediate remediation data. TechRadar frames the event as a broader security warning, emphasizing the potential for downstream project compromise without detailing the specific package list or download metrics.

Comparison summary

AI-assisted · Cerebras / Llama · just generated or not yet stored · inspect sources below rather than trusting this alone

The Shai-Hulud malware campaign expanded to compromise 314 npm packages, including size-sensor and echarts-for-react, after a maintainer account was hijacked. This incident resulted in 631 malicious versions being published, impacting over 15 million monthly downloads. Both outlets confirm the scale of the breach and the specific packages involved.

Coverage diverges primarily in technical granularity versus general advisory tone. SafeDep provides a precise inventory of affected libraries and quantifies the exact number of malicious versions, catering to developers needing immediate remediation data. TechRadar frames the event as a broader security warning, emphasizing the potential for downstream project compromise without detailing the specific package list or download metrics.

Neither outlet specifies the exact timeline of the initial account compromise or the specific payload mechanisms used by the malware. This omission limits the ability for security teams to identify if other, unlisted packages share the same vulnerability vector. The lack of forensic detail is a shared blindspot across the center-leaning sources.

How to read these numbers
Article count is not confirmation count. Wire rewrites and same-outlet follow-ups inflate totals. Prefer distinct publishers and primary links on each story page.

Report timeline

Oldest → newest among clustered members. Gaps may mean delayed pickup, not silence.

  1. May 18, 2026, 10:04 PM
    SafeDep - Real-time Open Source Software Supply Chain Security · Center
    Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
  2. May 20, 2026, 8:35 AM

Headline framing

Vocabulary fingerprints · not a political endorsement

Both outlets report on the Mini Shai-Hulud campaign targeting npm packages. The Hacker News headline highlights the recurring nature of the threat and cites a specific count of 314 packages. TechRadar reports a higher figure of over 600 packages, explicitly naming the hackers and urging developers to remain vigilant. Both sources maintain a neutral, technical tone focused on the security incident.

Per-source framing
Center
Hacker News
Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
Strikes AgainCompromised
Focuses on the recurrence of the attack and the specific scale of the breach.
Center
TechRadar
Mini Shai-Halud hackers publish over 600 compromised npm packages — developers warned to be on their guard
hackerscompromisedwarned
Emphasizes the actor's actions and issues a direct advisory to the developer community.

Bias/ownership: published methodology on source profiles · AI text always labeled · no reader paywall · no engagement ranking of news · transparency · contribute Ws · home