// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
Breach Record

antv

DISCLOSED 2026-05-20 · STOLEN CREDS

A threat actor compromised an @antv maintainer account and published malicious versions of widely used npm data-visualization packages. The malicious payload executes during npm install, targeting GitHub Actions environments to steal credentials from multiple platforms. The attack propagated through dependency chains, affecting downstream packages with millions of weekly downloads.

The record

What we know

Disclosed
2026-05-20
Attack vector
Stolen Creds
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the antv disclosure. It updates if new public reporting emerges. All tracked breaches →

antv just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →