logo

Attackers Weaponize SAP npm Packages to Steal GitHub, Cloud, and AI Coding Tool Secrets

ID: c3052eb9-c744-5035-8189-84abc9b6edc2

STIX ID: report--c3052eb9-c744-5035-8189-84abc9b6edc2

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

A supply-chain campaign compromised four official SAP npm packages (mbt, @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service) by adding a hidden preinstall (setup.mjs) that fetches Bun and runs an obfuscated execution.js payload (“Mini Shai-Hulud”) which harvests npm tokens, GitHub and cloud credentials, AI tool artifacts, SSH keys and CI secrets, encrypts exfiltrated data, and uploads it to GitHub dead-drop repositories; affected hosts should treat all secrets as exposed, uninstall the malicious package versions, reinstall clean versions with --ignore-scripts, search for large execution.js/.claude artifacts and unauthorized workflows, and rotate all credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.