Browse Source
The npm @antv/* packages (g2, g6, x6, l7, f2, data-set) were compromised in a supply-chain attack on 2026-05-19. Malicious versions embed credential-stealing payloads in preinstall scripts. This project depends on @antv/g2@5.4.8 via @ant-design/plots, which is safe. However, the semver range ^5.2.7 would allow npm to resolve 5.5.8 or 5.6.8 (compromised) on a fresh install or lockfile regeneration. Add an npm override to constrain @antv/g2 to >=5.2.7 <5.5.8, preventing resolution of the known-malicious versions. This can be relaxed once clean versions above 5.6.8 are published. Ref: https://socket.dev/blog/antv-packages-compromised Ref: https://github.com/antvis/G2/issues/7394 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>pull/11798/head
1 changed files with 3 additions and 0 deletions
Loading…
Reference in new issue