Decision RecordActivePublished without chair review

Contain suspected malicious npm package execution

npm and CI supply-chain containment

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
High
Section support
High confidence · 1/8 backed · 2 gaps · panel
Severity
High
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v1
Last updated today
Last revised 2026-08-23
Active3 evidence references · Published 23 Aug 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

Freeze workflows that may have executed affected packages, preserve runner and package evidence, revoke reachable credentials after suspected execution, pin verified-clean versions, and rebuild on clean infrastructure before restoring publication.

Public guidance

Current public guidance · the full record

Current public value version · v1
01

What to do now

At a glance

The edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.

02

Why now

Supported

On August 23, 2026, the supply-chain assessment reported renewed activity across the antv, timeago, and size-sensor package families and characterized the maintainer account and npm publication path as the trust failure.

The same assessment says lifecycle-script execution can expose credentials available to a CI job and make resulting artifacts untrusted.

The defense architect therefore prioritized freezing npm publishing and CI workflows, preserving runner images, and containing credentials before publication continues.

Because exact affected versions remain unavailable, action is triggered by possible execution rather than a family-wide claim of compromise.

03

Who is affected

Partially supported

Affected populations are: maintainers and dependency operators using implicated antv, timeago, or size-sensor packages or transitive dependencies, whose lockfiles may show exposure without proving execution; CI administrators operating runners that installed and executed a malicious lifecycle script, because credentials available to the job may have been exposed; npm registry, release, and publication operators whose credentials were reachable from those jobs; and downstream consumers of artifacts produced on a runner after execution, because those artifacts must be treated as untrusted. Exact versions and deployment counts are unavailable.

04

What supports this

Partially supported

Support: The supply-chain analyst’s August 23, 2026 assessment describes the maintainer account and npm publication path as the trust failure, reports a renewed cascade involving the antv, timeago, and size-sensor package families, and says earlier Microsoft analysis connected the campaign with CI/CD credential theft.

Support: The same assessment distinguishes lockfile exposure from compromise and says lifecycle-script execution on a runner exposes credentials available to that job and makes resulting artifacts untrusted.

Support: The defense architect’s August 23, 2026 operational assessment calls for freezing npm publishing and CI workflows, preserving runner images, and revoking package-registry and reachable CI secrets.

Support: The evidence review found the containment, credential revocation, verified-clean version pinning, fresh rebuild, and publication hold supported. Limitation: A separate evidence-gap review found that complete affected-version coverage was unavailable, preventing precise workflow scoping.

05

How the Roundtable reached this

Partially supported

The supply-chain analyst identified the maintainer account and npm publication path as the trust boundary, reported activity across the antv, timeago, and size-sensor package families, and distinguished lockfile exposure from executed compromise.

The defense architect converted that assessment into containment steps: freeze npm publishing and CI workflows, preserve runner images, then revoke package-registry and reachable CI secrets.

The decision scout framed lifecycle-script execution as the trigger for treating credentials and resulting artifacts as untrusted. The evidence review supported those actions but challenged the ability to identify every affected workflow because the complete version list was unavailable.

The boundary review resolved that limitation by keeping the scope conditional. The linker found no prior decision to update, and the arbiter selected a new operational decision on that basis.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 10 candidate signals.
  • Linker (AI panel role)Linker evaluated 10 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 21 evidence signals; 11 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 0 predictions and rejected 2 claims.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 14 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 10 decision envelopes.

Key disagreement

Scout (AI panel role)

The complete affected-version set was not established, and a lockfile match proves exposure rather than execution or compromise.

Arbiter outcome

Arbiter outcome: new decision record. The supply-chain containment and trust-recovery actions are strongly supported, and conditional scoping addresses the incomplete affected-version list.

Candidates considered

Considered 10 candidates · opened 1 · 9 not opened (9 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Conflicting

The complete affected-version set for the antv, timeago, and size-sensor package families was not established.

A matching lockfile entry demonstrates exposure, not installation, lifecycle-script execution, credential theft, or artifact compromise.

The record contains no organization-specific build data, so it does not establish which CI runners, publication jobs, credentials, or downstream artifacts were actually exposed.

07

What evidence is missing

Conflicting

The record lacks an authoritative package-and-version list for the antv, timeago, and size-sensor families.

It also lacks the underlying Semgrep and Microsoft materials cited by the supply-chain analyst, organization-specific dependency inventories, and runner and package evidence showing whether a lifecycle script executed.

No deployment-specific record identifies which credentials were reachable, which artifacts were produced after possible execution, or whether verified-clean versions and maintainer trust have been re-established.

08

What would change this

Partially supported

An authoritative version list would narrow containment for antv, timeago, and size-sensor versions shown to be unaffected or expand it to newly identified versions.

Evidence that no implicated lifecycle script executed would reduce a lockfile match from suspected compromise to exposure and could remove the execution-triggered credential and artifact response. Confirmed execution would preserve the broader response.

Publication can resume when verified-clean versions are pinned, exposed credentials are replaced, artifacts are rebuilt on fresh infrastructure, and maintainer and npm publication-path trust are restored.

09

What to watch next

Partially supported

Watch for an authoritative affected-version list for the antv, timeago, and size-sensor package families; use it to narrow or expand the frozen workflow set.

Check preserved runner and package evidence for lifecycle-script execution; confirmed execution triggers revocation of every credential reachable by that job and rejection of its artifacts.

Before restoring publication, verify clean package versions, successful reproduction on fresh runners, replacement of exposed secrets, and restoration of maintainer and npm publication-path trust.

Sources & context

Evidence basis

3 references
Context
**30 minutes — contain and preserve.** Alex and Lena are right: 361 observed IPs are leads, not confirmed victims, so do…

**30 minutes — contain and preserve.** Alex and Lena are right: 361 observed IPs are leads, not confirmed victims, so do not trigger four indiscriminate patch waves. Isolate internet-facing Zimbra matching Maya’s pre-10.1.20/service conditi…

Observed 23 Aug 2026
Context
The trust failure is the **maintainer account and npm publication path**, not a normal code defect. Semgrep reports the …

The trust failure is the **maintainer account and npm publication path**, not a normal code defect. Semgrep reports the renewed cascade across the `antv`, `timeago`, and `size-sensor` package families; Microsoft’s earlier analysis ties the …

Observed 23 Aug 2026
Revision trail

Public value history

1 event on record
1 value version · 1 update · 0 predictions
  1. 23 Aug 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.