BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Supply chain attack hits SAP npm packages with malware

SAP npm packages hijacked by malware stealing secrets via GitHub in 2026.

  • A supply chain attack compromised four key SAP-related npm packages with credential-stealing malware on April 29, 2026.
  • The malware, self-titled mini Shai-Hulud, steals developer and cloud secrets, encrypts them, and exfiltrates data to over 1,100 GitHub repositories.
  • This is one of the first attacks to target AI coding agent configurations for persistence, using hooks in VS Code and Claude Code.
  • The attack was enabled by exploiting a misconfigured OIDC trusted publisher workflow in a GitHub Actions repository.

Cybersecurity researchers exposed a new supply chain attack on April 29, 2026, compromising SAP-related npm packages with sophisticated credential-stealing malware according to reports. Dubbed mini Shai-Hulud, the campaign specifically targeted packages like mbt and three @cap-js modules used in the SAP JavaScript development ecosystem.

- Advertisement -

The malicious versions introduced a preinstall script that downloaded and executed a payload, a detail confirmed by Socket. This payload was designed to harvest developer credentials, GitHub and npm tokens, and secrets from major cloud platforms including AWS, Azure, and GCP.

Consequently, the stolen data was encrypted with AES-256-GCM and sent to public GitHub repositories created on victim accounts. The malware also gained persistence by injecting files into repositories to trigger execution when opened in code editors like VS Code.

Meanwhile, Wiz noted the attack shares features with prior TeamPCP operations, suggesting the same threat actor. The attackers compromised a developer account and exploited a critical configuration gap in npm‘s OIDC trusted publishing.

SafeDep explained the publisher configuration for one package trusted any workflow, not just the canonical one. This allowed a branch push to obtain a token for publishing the malicious packages without proper provenance.

- Advertisement -

In response, the maintainers and the cds-dbs team have released new, safe versions to supersede the compromised ones. StepSecurity highlighted this as a pioneering attack vector for targeting AI coding agent configurations.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Stable Sea Adds Tokenized Treasury Fund for Corporate Cash

Stable Sea integrated the WisdomTree Government Money Market Digital Fund (WTGXX) to help businesses...

Sky Reports Record Q1 Revenue As Token Value Declines

Sky posted record Q1 2026 revenue of nearly $124 million, its highest since launching...

Farage’s Secret $6.7M Gift From Tether Investor Revealed

Christopher Harborne, a Tether stakeholder, gave Nigel Farage a previously undisclosed $6.7 million personal...

Robinhood’s 11 Businesses Top $100M Revenue

Robinhood Markets CEO Vlad Tenev emphasized the company's diversified business, with 11 distinct lines...

Computershare Partners to Tokenize Corporate Shares

Computershare, a major financial services firm and transfer agent for 58% of the S&P...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading