Shai-Hulud Strikes SAP: Supply Chain Worm Weaponized Claude Code to Compromise the CAP Framework
ID: 84d5bb3d-3771-55f8-9845-58bc0a204ee5
STIX ID: report--84d5bb3d-3771-55f8-9845-58bc0a204ee5
Feed Name: Security Boulevard
On April 29, 2026 a supply-chain campaign compromised four SAP CAP npm packages by using malware delivered via a preinstall hook that installed a multi-stage obfuscated payload; the attacker leveraged a developer’s Claude Code GitHub integration to commit malicious workflow changes that executed the malware inside GitHub Actions, extracted an npm OIDC publish token, and published infected package versions that exfiltrate credentials, deploy persistence (Claude SessionStart hooks), and propagate via npm republishing and repository-resident droppers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
