Find notable cyber news and cases, enriched with sources, timelines, and signals.

Mini Shai-Hulud SAP-related npm supply-chain campaign

Campaign
First reported
Last updated
Happening score
H score 45
1 unique sources, 2 articles

Summary

Hide ▲

A new Mini Shai-Hulud supply-chain campaign is targeting SAP-related npm packages, putting developer and CI/CD environments at risk of credential theft and malicious package propagation. The poisoned releases published on April 29, 2026 used a preinstall flow to bootstrap Bun, execute malware, and exfiltrate secrets. The operation matters because it can spread through trusted package and workflow paths while stealing GitHub/npm tokens and cloud secrets.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

AsyncAPI repositories and npm publishing workflow hit by network compromise

Incident
H score27 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...

GitHub fake-repository infostealer campaign

Campaign
H score41 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...

Jscrambler hit by network compromise

Incident
H score15 First: 13.07.2026 22:44 Last: 13.07.2026 22:44 Sources 1

About this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

Timeline

  1. 12.05.2026 11:50 1 articles · 2mo ago

    Mini Shai-Hulud spreads to TanStack and PyPI packages

    Campaign Scope Update

    Mini Shai-Hulud expands beyond the original SAP-related npm packages to compromise TanStack, UiPath, Mistral AI, OpenSearch, Guardrails AI, and DraftLab packages across npm and PyPI, with malicious payloads using router_init.js, GitHub Actions abuse, and exfiltration to filev2.getsession[.]org, api.masscan[.]cloud, or attacker-controlled GitHub repositories.

    Show sources
  2. 29.04.2026 19:26 1 articles · 2mo ago

    Mini Shai-Hulud publishes malicious SAP-related npm packages

    Exploitation Observed

    The Mini Shai-Hulud campaign published poisoned releases for [email protected], @cap-js/[email protected], @cap-js/[email protected], and @cap-js/[email protected], adding a package.json preinstall hook that loads setup.mjs, downloads a platform-specific Bun ZIP from GitHub Releases, and runs execution.js to steal credentials and propagate through developer and release workflows.

    Show sources
  3. 29.04.2026 19:26 1 articles · 2mo ago

    Researchers analyze Mini Shai-Hulud credential theft and persistence

    Technical Analysis Update

    Researchers from Aikido Security, Onapsis, OX Security, SafeDep, Socket, StepSecurity, and Wiz described Mini Shai-Hulud as a supply-chain campaign affecting SAP's JavaScript and cloud application development ecosystem, noted that the malware harvests local developer credentials, GitHub and npm tokens, GitHub Actions secrets, and cloud secrets from AWS, Azure, GCP, and Kubernetes, and said the payload exfiltrates data to victim-owned GitHub repositories while injecting .claude/settings.json and .vscode/tasks.json for persistence. Wiz also said the packages share features with prior TeamPCP operations and use a TeamPCP-linked shared RSA public key.

    Show sources