Skip to content
A Mini Shai-Hulud Targeting the SAP Ecosystem

A Mini Shai-Hulud Targeting the SAP Ecosystem

Blog.Gitguardian April 29, 2026

Earlier today, Aikido researchers detected multiple compromised Node.js packages in SAP's namespace today. The malware adapts to CI environments, steals GitHub personal access tokens, and uses them to self-propagate—a pattern consistent with recent supply-chain attacks.

The RSA keys used to encrypt the exfiltrated secrets are the same as the ones used last week in the @bitwarden/cli attack .

GitGuardian identified 7 commits containing exposed ghp_ tokens—all remain valid and active at 16h46 EST. The attacker used the stolen tokens to create public repositories, each named with Dune-themed keywords. Inside each repository:

Our telemetry shows the attack's full scope:

Extracted Entities

Attack Types (1)

Campaigns (1)

Companies (1)

Malware (1)

Platforms (1)