Compromised SAP npm Packages Found Harvesting Developer and CI/CD Secrets
ID: 98a4bcc5-a409-5531-9931-77269f1a3b6e
STIX ID: report--98a4bcc5-a409-5531-9931-77269f1a3b6e
Feed Name: GBHackers
**Executive Summary:** The report details a high-risk supply-chain campaign named "Mini Shai Hulud" by TeamPCP that compromised several SAP npm packages by adding a pre-install dropper (setup.mjs) which downloads the Bun runtime to execute an obfuscated payload (execution.js) that steals developer and CI/CD credentials, cloud secrets, and browser-stored passwords, propagates via editor/CI hooks and repository poisoning, and exfiltrates data to attacker-controlled GitHub repositories; SHA-256 indicators for the malicious files are provided and remediation guidance includes rotating tokens, scanning lockfiles and CI logs, and monitoring for unauthorized GitHub activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
