May 2026 saw consecutive npm supply-chain emergencies already indexed on BreachHistory: the node-ipc malicious CJS stealer publishes (May 14) and the Mini Shai-Hulud maintainer compromise through atool affecting 639 malicious versions across 323 packages (May 19), including the AntV visualization ecosystem and widely used unscoped modules such as echarts-for-react.
Review package incidents: BreachHistory package supply-chain index. Primary IDs: pkg-npm-node-ipc-cjs-stealer-202605, pkg-npm-antv-mini-shai-hulud-20260519.
Sources: StepSecurity, Socket