TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
ID: 77742b30-79a2-5912-9090-1e03b451e312
STIX ID: report--77742b30-79a2-5912-9090-1e03b451e312
Feed Name: Dark Reading
TeamPCP conducted a supply-chain campaign (dubbed "Mini Shai-Hulud") by injecting malicious preinstall scripts into four SAP-related npm packages (@cap-js/sqlite v2.2.2, @cap-js/postgres v2.2.2, @cap-js/db-service v2.10.1, and mbt v1.2.48). The multi-stage payload harvests GitHub, npm, Kubernetes, CI/CD, and cloud credentials, encrypts and exfiltrates them to attacker-controlled GitHub repositories, and contains propagation code to compromise additional packages and downstream organizations; packages were removed after detection, but hundreds of thousands of downloads and exposure risk make the incident high impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
