logo

The never-ending supply chain attacks worm into SAP npm packages, other dev tools

ID: 0dc7dd78-ccaf-5471-96f8-c051c17199a0

STIX ID: report--0dc7dd78-ccaf-5471-96f8-c051c17199a0

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-05-06

...
...

TeamPCP's "Mini Shai-Hulud" supply-chain campaign compromised multiple widely used npm packages (including SAP-related packages and intercom-client) and PyPI lightning releases, deploying multi-stage credential‑stealing malware that executes via preinstall scripts or on import, extracts developer and CI/CD secrets (GitHub tokens, cloud credentials, runner memory), self‑propagates, encrypts stolen data and exfiltrates it to public GitHub repositories under victims' accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.