CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

SAP npm Package Supply Chain Attack Leveraging "Mini Shai-Hulud" Credential Malware via AI Tool Configuration Abuse

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A coordinated supply chain attack compromised multiple SAP-related npm packages with credential-stealing malware dubbed "Mini Shai-Hulud". The attack introduced malicious preinstall scripts in affected package versions, which downloaded and executed a 11.6 MB payload from GitHub Releases at installation time, targeting developer and CI/CD environments. Stolen credentials from GitHub, npm, AWS, Azure, GCP, Kubernetes, and other services were encrypted and exfiltrated to attacker-controlled repositories labeled "A Mini Shai-Hulud has Appeared". The attack also abused AI coding agent configurations in VS Code and Claude Code for persistence and propagation.

Timeline

  1. 29.04.2026 19:26 1 articles · 2h ago

    SAP npm Package Supply Chain Compromise via Mini Shai-Hulud Malware Disclosed

    Compromised npm packages [email protected], @cap-js/[email protected], @cap-js/[email protected], and @cap-js/[email protected] were published on April 29, 2026, between 09:55–12:14 UTC, each including malicious preinstall hooks that downloaded and executed a 11.6 MB credential-stealing payload from GitHub Releases. The malware harvested and encrypted developer and cloud secrets, exfiltrating them to attacker-controlled GitHub repositories, while self-propagating via GitHub Actions workflow injection and abusing AI tool configurations for persistence on VS Code and Claude Code.

    Show sources

Information Snippets