logo

'Mini Shai-Hulud' supply chain attack targets SAP npm packages

ID: 18aca411-8a84-56c7-ab6c-b7318c3f3837

STIX ID: report--18aca411-8a84-56c7-ab6c-b7318c3f3837

Feed Name: Sophos Blogs

Threat Score
70/100

Date Published: 2026-04-29

Date Updated: 2026-04-30

...
...

On April 29, 2026, researchers reported the 'mini Shai-Hulud' campaign in which compromised npm packages for SAP's Cloud Application Programming Model (CAP) include code to steal credentials, encrypt them, and exfiltrate the data to public GitHub repositories. Maintainers have released updated package versions; organizations are advised to investigate installations of the compromised packages, review GitHub, npm, and cloud activity for exposed credentials, and rotate any potentially affected secrets. Sophos detections referenced include JS/Agent-BMAH and JS/Steal-EAT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.