The “Mini Shai-Hulud” Attack Hijacking SAP Developer Pipelines
ID: 527a2b3e-8a65-5143-89ca-b0ee31140b03
STIX ID: report--527a2b3e-8a65-5143-89ca-b0ee31140b03
Feed Name: securityonline.info
Security researchers have identified a precision supply-chain compromise of SAP developer packages and Cloud MTA build workflows where malicious npm preinstall hooks run a setup.mjs that downloads the Bun JavaScript runtime to execute an obfuscated 11.7 MB payload (execution.js). The payload is a credential-stealing and propagation framework that harvests GitHub/npm tokens, cloud provider secrets (AWS STS, Azure Key Vault, GCP Secret Manager), Kubernetes tokens, and CI/CD runner secrets, exfiltrates data to public GitHub repositories (with a distinctive Dune-themed description), and uses a commit-message propagation token (OhNoWhatsGoingOnWithGitHub) to find and spread via exposed base64-encoded GitHub tokens; defenders are urged to search for compromised package versions (e.g., @cap-js/sqlite v2.2.2) and rotate all affected secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
