logo

SAP Ecosystem Targeted: The Mini Shai-Hulud Supply Chain Attack

ID: 44f2db86-b209-5696-bdf3-93ea7a340b4e

STIX ID: report--44f2db86-b209-5696-bdf3-93ea7a340b4e

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-05-03

Author: Ameer Owda

...
...

A sophisticated npm supply-chain campaign named "Mini Shai-Hulud" has compromised several SAP CAP-related packages by adding a malicious preinstall hook that fetches a Bun runtime and executes a credential-stealing payload. The malware harvests SSH keys, cloud credentials, Kubernetes configs, CI secrets (including memory scraping of masked secrets), and AI/IDE configuration backdoors, exfiltrating data via newly created GitHub repositories while using stolen tokens to propagate to other packages; immediate dependency audits, secret rotation, IoC hunts, and GitHub activity monitoring are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.