HomeSecurity'Mini Shai-Hulud': SAP-Related npm Packages Compromised with Credential Stealer

'Mini Shai-Hulud': SAP-Related npm Packages Compromised with Credential Stealer

Cybersecurity researchers are sounding the alarm about a new supply chain attack targeting SAP-related npm Packages with credential- stealing. According to reports from Aikido Security, SafeDep, Socket, StepSecurity , and Wiz, the campaign calling itself mini Shai-Hulud has affected the following packages connected to SAP's JavaScript and cloud application development ecosystem:

  • mbt@1.2.48
  • @cap-js/db-service@2.10.1
  • @cap-js/postgres@2.2.2
  • @cap-js/sqlite@2.2.2
Mini Shai-Hulud SAP-Related npm

The affected versions introduced new installation behavior that was not previously part of the expected functionality of these packages,” Socket said. “The malicious versions added a preinstall script that acts as a runtime bootstrapper, downloading a platform-specific Bun ZIP from GitHub Releases, extracting it, and directly executing the extracted Bun binary.”

The implementation also follows HTTP redirects without validating the destination and uses PowerShell with -ExecutionPolicy Bypass on Windows, increasing the risk to affected developers and CI/CD environments“.

See also: GitHub fixed critical RCE vulnerability in less than 6 hours

Wiz noted that the malicious packages closely match those from previous TeamPCP, indicating that the same threat actor is likely behind the latest campaign.

The suspicious versions were published on April 29, 2026, between 09:55 UTC and 12:14 UTC.

The malicious packages insert a new preinstall hook in package.json that executes a file named “setup.mjs.” This acts as a loader for the Bun JavaScript runtime to execute the credential stealer and propagation framework (“execution.js”).

Mini Shai-Hulud: Data theft via malicious npm packages

According to Aikido, the malware is designed to collect local developer credentials, GitHub and npm tokens, GitHub Actions secrets, and cloud secrets from AWS, Azure, GCP, and Kubernetes.

The stolen data is encrypted and exported to public GitHub repositories created on the victim's account with the description "A Mini Shai-Hulud has Appeared".

See also: Critical authentication vulnerability in cPanel – Update now

'Mini Shai-Hulud': SAP-Related npm Packages Compromised with Credential Stealer

As of this writing, there are over 1,100 repositories with this description. Additionally, the 11.6 MB payload has the ability to self-propagate via developer and release workflows, specifically using GitHub and npm tokens to inject a malicious GitHub Actions workflow into the victim's repositories. The goal is to steal repository secrets and publish poisoned versions of npm packages to the registry.

However, the latest incident bears significant differences from previous Shai-Hulud attacks:

– All extracted data is encrypted with AES-256-GCM and includes the key using RSA-4096 with a public key embedded in the payload.

– Available on systems with Russian locale.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

– The payload is bound to every accessible GitHub repository by injecting a “.claude/settings.json” file that abuses Claude Code’s SessionStart hook and a “.vscode/tasks.json” file with a “runOn” setting of “folderOpen”. As a result, any attempt to open the infected repository in Microsoft Visual Studio Code (VS Code) or Claude Code causes the malware to execute.

This is one of the first supply chain targeting the configuration settings of AI coding agents as a vector of persistence and propagation,” StepSecurity said.

Wiz also reported that recent Checkmarx and Bitwarden detected a check for Russian locales, adding that the attack leverages a shared RSA public key, linked to TeamPCP, to encrypt the extracted data.

See also: CISA: ConnectWise and Windows vulnerabilities in the KEV Catalog

SAP, according to Wiz researchers, adds the ability to steal credentials from various browsers such as Chrome, Safari, Edge, Brave, and Chromium, as well as export saved passwords. This feature was not available in previous versions. At the same time, exporting via GitHub to Dune themed repos (which initially served as an alternative C2 channel for the Bitwarden CLI) is now the main method.

'Mini Shai-Hulud': SAP-Related npm Packages Compromised with Credential Stealer

Analysis showed that the attackers compromised the RoshniNaveenaS for three “@cap-js” packages, then pushed a modified workflow to a non-master branch and used an extracted npm OIDC token to publish malicious packages without origin. For mbt, the static npm token “cloudmtabot” is suspected to have been compromised via an as-yet-unspecified method.

In response to the incident, maintainers released patched versions that replace the compromised ones:

OX Security researchers Moshe Siman Tov Bustan and Nir Zadok emphasized that this campaign once again shows that GitHub is often used as a preferred C2 infrastructure for data extraction. As they noted, blocking github.com is not a practical solution for most development teams, and detecting such extractions becomes extremely difficult when GitHub acts as a delivery medium.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS