Back Blog.Gitguardian A Mini Shai-Hulud Targeting the SAP Ecosystem
Earlier today, Aikido researchers detected multiple compromised Node.js packages in SAP's namespace today. The malware adapts to CI environments, steals GitHub personal access tokens, and uses them to self-propagate—a pattern consistent with recent supply-chain attacks.
The RSA keys used to encrypt the exfiltrated secrets are the same as the ones used last week in the @bitwarden/cli attack .
GitGuardian identified 7 commits containing exposed ghp_ tokens—all remain valid and active at 16h46 EST. The attacker used the stolen tokens to create public repositories, each named with Dune-themed keywords. Inside each repository:
Our telemetry shows the attack's full scope:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
