Mini Shai-Hulud SAP-related npm supply-chain campaign
Campaign
Summary
Hide ▲
Show ▼
A new Mini Shai-Hulud supply-chain campaign is targeting SAP-related npm packages, putting developer and CI/CD environments at risk of credential theft and malicious package propagation. The poisoned releases published on April 29, 2026 used a preinstall flow to bootstrap Bun, execute malware, and exfiltrate secrets. The operation matters because it can spread through trusted package and workflow paths while stealing GitHub/npm tokens and cloud secrets.
Related Happenings
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
GitHub fake-repository infostealer campaign
Campaign
H score41
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
GitHub fake-repository infostealer campaign
CampaignAbout this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentAbout this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Timeline
-
12.05.2026 11:50 1 articles · 2mo ago
Mini Shai-Hulud spreads to TanStack and PyPI packages
Campaign Scope UpdateMini Shai-Hulud expands beyond the original SAP-related npm packages to compromise TanStack, UiPath, Mistral AI, OpenSearch, Guardrails AI, and DraftLab packages across npm and PyPI, with malicious payloads using router_init.js, GitHub Actions abuse, and exfiltration to filev2.getsession[.]org, api.masscan[.]cloud, or attacker-controlled GitHub repositories.
Show sources
- Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages — thehackernews.com — 12.05.2026 11:50
-
29.04.2026 19:26 1 articles · 2mo ago
Mini Shai-Hulud publishes malicious SAP-related npm packages
Exploitation ObservedThe Mini Shai-Hulud campaign published poisoned releases for [email protected], @cap-js/[email protected], @cap-js/[email protected], and @cap-js/[email protected], adding a package.json preinstall hook that loads setup.mjs, downloads a platform-specific Bun ZIP from GitHub Releases, and runs execution.js to steal credentials and propagate through developer and release workflows.
Show sources
- SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack — thehackernews.com — 29.04.2026 19:26
-
29.04.2026 19:26 1 articles · 2mo ago
Researchers analyze Mini Shai-Hulud credential theft and persistence
Technical Analysis UpdateResearchers from Aikido Security, Onapsis, OX Security, SafeDep, Socket, StepSecurity, and Wiz described Mini Shai-Hulud as a supply-chain campaign affecting SAP's JavaScript and cloud application development ecosystem, noted that the malware harvests local developer credentials, GitHub and npm tokens, GitHub Actions secrets, and cloud secrets from AWS, Azure, GCP, and Kubernetes, and said the payload exfiltrates data to victim-owned GitHub repositories while injecting .claude/settings.json and .vscode/tasks.json for persistence. Wiz also said the packages share features with prior TeamPCP operations and use a TeamPCP-linked shared RSA public key.
Show sources
- SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack — thehackernews.com — 29.04.2026 19:26