logo

SAP npm Packages Compromised to Harvest Developer and CI/CD Secrets

ID: df6a2a74-0436-591d-8692-1fcafbc3700f

STIX ID: report--df6a2a74-0436-591d-8692-1fcafbc3700f

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Guru Baran

...
...

A supply-chain campaign dubbed 'mini Shai Hulud' compromised four SAP Cloud Application Programming Model (CAP) npm packages by injecting a preinstall hook that downloads the Bun runtime and runs an obfuscated 11 MB second-stage payload which steals GitHub, npm, cloud (AWS/Azure/GCP), Kubernetes, and CI/CD secrets and self-propagates by republishing infected packages; researchers attribute the campaign to TeamPCP and publish affected package versions, tarball and dropper hashes alongside mitigation guidance (rotate secrets, audit CI/CD, block listed versions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.