On May 19, 2026, a compromised npm account pushed malicious versions of 323 packages across Alibaba's AntV ecosystem. The payload reads GitHub Actions runner memory to extract masked secrets in plaintext. Here is what happened, how it works, and what to do.