Skip to content

SAP npm Packages Compromised to Harvest Developer and CI/CD Secrets

Cybersecuritynews •Guru Baran • April 29, 2026

A new supply chain attack dubbed “mini Shai Hulud” has compromised four SAP-related npm packages by injecting malicious preinstall scripts that silently execute during dependency installation, targeting developer environments and CI/CD pipelines to steal credentials across GitHub, npm, and major cloud providers. Security researchers at StepSecurity, Aikido Security, SafeDep, Socket, and Wiz identified that malicious […]

Extracted Entities

Attack Types (1)

Campaigns (1)

Companies (1)

Platforms (1)

Tools (1)