New AI Incident Response, Multi-Region Agents, and Custom-Domain Status Pages — May 2026
Services Pricing Dashboard

Supply Chain Compromise on  @antv being investigated for more than 300 packages in npm ecosystem

Minor Impact Investigating Ongoing May 19, 2026

Incident Lifecycle

Investigating Investigating Investigating Investigating Investigating Investigating Investigating

Incident Timeline

Investigating
We are continuing to investigate this issue.
May 19, 2026 at 9:39 PM UTC
Investigating
The Compromised Packages list is now available at <a href="https://security.snyk.io/antv-supply-chain-compromise-may-2026">https://security.snyk.io/antv-supply-chain-compromise-may-2026</a>
May 19, 2026 at 10:44 AM UTC
Investigating
Our blog post is now available: <a href="https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/">Mini Shai-Hulud Hits AntV</a>
May 19, 2026 at 9:13 AM UTC
Investigating
Customers can now assess potential impact in the Snyk app by visiting: Analytics → Reports → Zero-Day → Active Security Incident Assessment for Antv Supply Chain Compromise - May 2026

Please continue to refer to the <a href="https://trust.snyk.io/updates">Snyk Trust Center</a> for the latest official updates and customer communications.
May 19, 2026 at 8:51 AM UTC
Investigating
The <a href="https://trust.snyk.io/updates">Snyk Trust Center</a> has been updated.
May 19, 2026 at 8:45 AM UTC
Investigating
Update:
Snyk is continuing to investigate and respond to the ongoing supply chain compromise of @antv and other packages.

Affected packages: Current findings indicate that multiple npm packages have been identified as affected, including packages within the @antv/* namespace and related packages outside the AntV namespace.

Scope:  Over 639 malicious package versions across more than 323 unique packages, with numbers subject to change

Cause: Investigations indicate the issue was caused by ...
May 19, 2026 at 7:55 AM UTC
Investigating
Current scope appears to be: over 630 malicious package versions across more than 315 unique packages, with the AntV suite heavily impacted.
This incident relates to compromised third-party open source packages in the npm ecosystem. There is no indication that Snyk systems, products, or infrastructure were compromised.
As an active investigation, this is subject to change.
We are currently working on confirming the known scope and providing vulnerability advice, reporting, blog, and Trust Cen...
May 19, 2026 at 5:29 AM UTC
Was your business affected by this Snyk outage?
Set up instant alerts for Snyk, be the first to know about outages via email, Slack, Teams, or Discord.