logo

Shai-Hulud Strikes SAP: Supply Chain Worm Weaponized Claude Code to Compromise the CAP Framework

ID: 84d5bb3d-3771-55f8-9845-58bc0a204ee5

STIX ID: report--84d5bb3d-3771-55f8-9845-58bc0a204ee5

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Tom Abai

...
...

On April 29, 2026 a supply-chain campaign compromised four SAP CAP npm packages by using malware delivered via a preinstall hook that installed a multi-stage obfuscated payload; the attacker leveraged a developer’s Claude Code GitHub integration to commit malicious workflow changes that executed the malware inside GitHub Actions, extracted an npm OIDC publish token, and published infected package versions that exfiltrate credentials, deploy persistence (Claude SessionStart hooks), and propagate via npm republishing and repository-resident droppers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.