Attackers Weaponize SAP npm Packages to Steal GitHub, Cloud, and AI Coding Tool Secrets
ID: c3052eb9-c744-5035-8189-84abc9b6edc2
STIX ID: report--c3052eb9-c744-5035-8189-84abc9b6edc2
Feed Name: cybersecurityNews.com
A supply-chain campaign compromised four official SAP npm packages (mbt, @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service) by adding a hidden preinstall (setup.mjs) that fetches Bun and runs an obfuscated execution.js payload (“Mini Shai-Hulud”) which harvests npm tokens, GitHub and cloud credentials, AI tool artifacts, SSH keys and CI secrets, encrypts exfiltrated data, and uploads it to GitHub dead-drop repositories; affected hosts should treat all secrets as exposed, uninstall the malicious package versions, reinstall clean versions with --ignore-scripts, search for large execution.js/.claude artifacts and unauthorized workflows, and rotate all credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
