logo

Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware

ID: 079a888b-6d5b-5971-acad-a6a0c16cc014

STIX ID: report--079a888b-6d5b-5971-acad-a6a0c16cc014

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2026-04-29

Date Updated: 2026-05-01

...
...

A TeamPCP supply-chain campaign dubbed “Mini Shai Hulud” compromised multiple SAP-related npm packages by adding preinstall scripts that deploy a Bun-based dropper and an obfuscated second-stage credential-stealer which targets developer machines and CI/CD pipelines to harvest GitHub/npm/cloud/Kubernetes/CI secrets, exfiltrate them via attacker-controlled GitHub repositories, and propagate to other repositories and developer tools; the report includes IOCs (malicious files and hashes), attribution evidence, and immediate mitigations (search/rotate credentials, audit GitHub activity).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.