Skip to content

Compromised SAP npm Packages Found Harvesting Developer and CI/CD Secrets

Gbhackers •Divya • April 30, 2026

Security researchers have identified a severe supply chain attack targeting the SAP developer ecosystem. A threat group identified as TeamPCP has compromised multiple legitimate SAP npm packages in a new campaign named Mini Shai Hulud. The operation relies on injecting malicious pre-install scripts that execute silently during dependency installation. By leveraging a multi-stage payload, the […]

Extracted Entities