{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-07-23T09:01:51.185Z"
  },
  "data": {
    "id": "incident_statuspage_snyk_wf4f6x8tt3sb",
    "slug": "snyk-supply-chain-compromise-on-antv-being-investigated-for-more-than-300-2026-05-19-6x8tt3sb",
    "title": "Supply Chain Compromise on  @antv being investigated for more than 300 packages in npm ecosystem",
    "summary": "Supply Chain Compromise on  @antv being investigated for more than 300 packages in npm ecosystem",
    "status": "resolved",
    "severity": "minor",
    "startedAt": "2026-05-19T05:29:25+00:00",
    "updatedAt": "2026-05-20T14:57:27.446+00:00",
    "resolvedAt": "2026-05-20T14:57:27.426+00:00",
    "provider": {
      "slug": "snyk",
      "name": "Snyk"
    },
    "affectedServices": [
      {
        "slug": "snyk-scanning",
        "name": "Vulnerability scanning"
      }
    ],
    "links": {
      "html": "/incidents/snyk-supply-chain-compromise-on-antv-being-investigated-for-more-than-300-2026-05-19-6x8tt3sb",
      "api": "/api/v1/incidents/snyk-supply-chain-compromise-on-antv-being-investigated-for-more-than-300-2026-05-19-6x8tt3sb",
      "providerHtml": "/providers/snyk"
    },
    "impactSummary": "Snyk reported a minor event for the affected tracked services.",
    "source": {
      "id": "source_snyk_status",
      "kind": "official_api",
      "name": "Snyk Status",
      "checkedAt": "2026-07-23T08:55:03.71+00:00",
      "officialUrl": "https://status.snyk.io",
      "statusPageUrl": "https://status.snyk.io"
    },
    "updates": [
      {
        "id": "update_statuspage_snyk_wf4f6x8tt3sb_7fwt5302nhfj",
        "status": "investigating",
        "body": "Current scope appears to be: over 630 malicious package versions across more than 315 unique packages, with the AntV suite heavily impacted.\nThis incident relates to compromised third-party open source packages in the npm ecosystem. There is no indication that Snyk systems, products, or infrastructure were compromised.\nAs an active investigation, this is subject to change.\nWe are currently working on confirming the known scope and providing vulnerability advice, reporting, blog, and Trust Center updates.\nPlease subscribe to this incident for further updates as they become available. Links to additional resources will be provided here.",
        "createdAt": "2026-05-19T05:29:25.82+00:00"
      },
      {
        "id": "update_statuspage_snyk_wf4f6x8tt3sb_x4dng2wvv0bs",
        "status": "investigating",
        "body": "Update:\nSnyk is continuing to investigate and respond to the ongoing supply chain compromise of @antv and other packages.\n\nAffected packages: Current findings indicate that multiple npm packages have been identified as affected, including packages within the @antv/* namespace and related packages outside the AntV namespace.\n\nScope:  Over 639 malicious package versions across more than 323 unique packages, with numbers subject to change\n\nCause: Investigations indicate the issue was caused by a compromised npm maintainer account, enabling automated malicious package publishing.\n\nImmediate action you can take:\n-Review dependency trees and lockfiles for affected packages, including packages within the @antv/* namespace and additional impacted npm packages size-sensor, echarts-for-react, timeago.js., canvas-nest.js\n-Pin to pre-May 19 versions, run npm install --ignore-scripts, rotate all credentials.\n\nWe will update here as soon as we have additional information or links",
        "createdAt": "2026-05-19T07:55:01.307+00:00"
      },
      {
        "id": "update_statuspage_snyk_wf4f6x8tt3sb_wsr60fchmb6v",
        "status": "investigating",
        "body": "The <a href=\"https://trust.snyk.io/updates\">Snyk Trust Center</a> has been updated.",
        "createdAt": "2026-05-19T08:45:51.072+00:00"
      },
      {
        "id": "update_statuspage_snyk_wf4f6x8tt3sb_zwv4xfk6wy1j",
        "status": "investigating",
        "body": "Customers can now assess potential impact in the Snyk app by visiting: Analytics → Reports → Zero-Day → Active Security Incident Assessment for Antv Supply Chain Compromise - May 2026\n\nPlease continue to refer to the <a href=\"https://trust.snyk.io/updates\">Snyk Trust Center</a> for the latest official updates and customer communications.",
        "createdAt": "2026-05-19T08:51:31.921+00:00"
      },
      {
        "id": "update_statuspage_snyk_wf4f6x8tt3sb_42060lptnfmj",
        "status": "investigating",
        "body": "Our blog post is now available: <a href=\"https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/\">Mini Shai-Hulud Hits AntV</a>",
        "createdAt": "2026-05-19T09:13:25.187+00:00"
      },
      {
        "id": "update_statuspage_snyk_wf4f6x8tt3sb_3xj9y6lt993j",
        "status": "investigating",
        "body": "The Compromised Packages list is now available at <a href=\"https://security.snyk.io/antv-supply-chain-compromise-may-2026\">https://security.snyk.io/antv-supply-chain-compromise-may-2026</a>",
        "createdAt": "2026-05-19T10:44:35.988+00:00"
      },
      {
        "id": "update_statuspage_snyk_wf4f6x8tt3sb_1965m6d7ytgp",
        "status": "investigating",
        "body": "We are continuing to investigate this issue.",
        "createdAt": "2026-05-19T21:39:44.72+00:00"
      },
      {
        "id": "update_statuspage_snyk_wf4f6x8tt3sb_9hn3mpdsgl7g",
        "status": "resolved",
        "body": "Customer Projects: This Status Page incident, “Supply Chain Compromise on AntV,” was opened to share customer-facing updates regarding a third-party compromise within the AntV ecosystem. Because AntV is a Snyk-supported ecosystem, we used this incident to alert customers that they may have projects using the affected package versions.\n\nSnyk Systems: Snyk’s security team has reviewed Snyk's systems, and there is no indication of compromise to Snyk systems, products, or infrastructure. As this issue does not impact the availability or operation of Snyk services, we are resolving this Status Page incident.\n\nGoing forward, customer-facing updates, affected package information, and remediation guidance for this issue will be provided through the Snyk Trust Center and related security resources. Snyk will continue to monitor for additional related advisories and update customer-facing resources as needed.",
        "createdAt": "2026-05-20T14:57:27.426+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}