logo

A Mini Shai-Hulud Targeting the SAP Ecosystem

ID: ae6e0fcf-43d7-5447-86c1-5e45de8395ee

STIX ID: report--ae6e0fcf-43d7-5447-86c1-5e45de8395ee

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Guillaume Valadon

...
...

Researchers found active malicious Node.js packages in the SAP namespace that steal GitHub personal access tokens from CI environments and use them to create attacker-owned repositories to exfiltrate encrypted secrets; the campaign has resulted in hundreds of public repos and dozens of accounts being used for exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.