logo

Compromised SAP npm Packages Found Harvesting Developer and CI/CD Secrets

ID: 98a4bcc5-a409-5531-9931-77269f1a3b6e

STIX ID: report--98a4bcc5-a409-5531-9931-77269f1a3b6e

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Divya

...
...

**Executive Summary:** The report details a high-risk supply-chain campaign named "Mini Shai Hulud" by TeamPCP that compromised several SAP npm packages by adding a pre-install dropper (setup.mjs) which downloads the Bun runtime to execute an obfuscated payload (execution.js) that steals developer and CI/CD credentials, cloud secrets, and browser-stored passwords, propagates via editor/CI hooks and repository poisoning, and exfiltrates data to attacker-controlled GitHub repositories; SHA-256 indicators for the malicious files are provided and remediation guidance includes rotating tokens, scanning lockfiles and CI logs, and monitoring for unauthorized GitHub activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.