logo

Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer

ID: 119d97b9-02b2-50c0-aadc-7347a7f2e5eb

STIX ID: report--119d97b9-02b2-50c0-aadc-7347a7f2e5eb

Feed Name: Aikido Security's Blog

Threat Score
88/100

Date Published: 2026-04-29

Date Updated: 2026-07-24

...
...

A supply-chain campaign compromised several npm packages used in the SAP developer ecosystem (`@cap-js/[email protected]`, `@cap-js/[email protected]`, `@cap-js/[email protected]`, `[email protected]`) by adding a `preinstall` script that downloads Bun and runs an obfuscated payload (`execution.js`) which harvests developer, CI, GitHub, npm and cloud credentials, scrapes GitHub runner memory, and exfiltrates encrypted results via public GitHub repositories (repositories labeled with the description "A Mini Shai-Hulud has Appeared"); the report includes hashes, markers, URLs, IOCs, likely initial access via a CircleCI PR build, propagation logic, and recommended detection and secret-rotation mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.