Compromised SAP npm Packages: The ‘Mini Shai-Hulud’ Supply Chain Attack

Pacchetti SAP npm Compromessi: L'Attacco "Mini Shai-Hulud" Colpisce la Supply Chain

On April 29, 2026, four official SAP npm packages were compromised in a significant supply chain attack. The operation, dubbed Mini Shai-Hulud, targeted critical tools used by thousands of enterprise developers worldwide.

The Mini Shai-Hulud Attack: What Happened

The Affected Packages and the Attack Vector

Four packages were involved: mbt@1.2.48, @cap-js/db-service@2.10.1, @cap-js/postgres@2.2.2, and @cap-js/sqlite@2.2.2. All belong to the SAP CAP and Cloud MTA ecosystem.

The attackers injected malicious scripts into the packages’ preinstall hooks — a mechanism that executes automatically during npm installation, requiring no user interaction whatsoever.

Once triggered, the script downloads the Bun runtime onto the victim’s system, which then runs malware specifically designed to steal sensitive credentials.

What Data Was Stolen

The malware had a clear objective: harvesting developer credentials and CI/CD pipeline secrets. Targets included:

  • GitHub tokens
  • npm credentials
  • Cloud secrets (AWS, Azure, GCP, Kubernetes)
  • SSH keys

Exfiltrated data was encrypted and sent to attacker-controlled GitHub repositories. The malware also self-propagated using the stolen GitHub tokens, exponentially expanding its reach.

Notably, the entire operation played out within a window of approximately two hours — an extremely narrow timeframe for detecting and containing the threat.

TeamPCP: The Threat Actor Behind the Operation

A Group With a Proven Track Record of npm Attacks

Researchers attribute the attack to TeamPCP with medium-to-high confidence. The attribution rests on shared technical indicators from previous campaigns, including identical RSA public keys, similar encoding routines, and the use of the Bun runtime as a delivery mechanism.

TeamPCP has been active in the npm ecosystem for at least two years, previously targeting packages tied to well-known security tools such as Trivy, Checkmarx, and Bitwarden. The recurring objective has always been the same: stealing credentials from development environments and CI/CD pipelines.

That said, the Mini Shai-Hulud variant introduces some notable new capabilities. It is the first to leverage AI coding agent configurations to establish persistence on compromised systems. Compared to earlier Shai-Hulud waves, this variant is both faster and more precisely targeted.

Impact and Response: How to Protect Against Supply Chain Attacks

Immediate Actions Taken by Package Maintainers

SAP package maintainers responded quickly, releasing clean versions of the compromised packages in short order. Users must update to the safe versions immediately.

The first step for any organization is to audit which package versions are deployed across their environments. Any installation of the compromised versions must be treated as a potential breach.

Recommendations for Managers and CISOs

Organizations need to act on both reactive and preventive fronts. Key priorities include:

Immediate actions:

  • Rotate all potentially exposed credentials — GitHub tokens, AWS/Azure/GCP keys, and SSH keys
  • Review npm installation logs for anomalous execution activity
  • Audit GitHub repositories for suspicious activity linked to compromised tokens

Structural measures:

  • Deploy runtime security platforms capable of blocking anomalous downloads such as the Bun binary retrieval
  • Implement systematic review of preinstall scripts before execution
  • Configure npm tokens with least-privilege access via OIDC, with per-workflow restrictions
  • Integrate supply chain monitoring tools such as Socket or Wiz for early detection

Beyond immediate remediation, organizations need to fundamentally rethink their trust model toward open-source packages — even when they originate from enterprise vendors like SAP. No package is immune to compromise.

It is worth stressing that the detection window is shrinking. Two hours is simply not enough time to mount an effective reactive response. Proactive security is now the only viable strategy against npm supply chain attacks.

Conclusions

The Mini Shai-Hulud attack marks a qualitative leap in TeamPCP’s tactics. Targeting official SAP packages means reaching high-criticality enterprise environments that organizations depend on daily. Any organization running SAP CAP or Cloud MTA must act immediately.

The software supply chain is now a primary attack vector. Ignoring it is no longer an option.

Sources: Wiz Blog, The Hacker News, Socket.dev Blog, BleepingComputer


The Mini Shai-Hulud attack on SAP npm packages is a stark reminder of how the software supply chain has become a critical threat vector for enterprise organizations. In this environment, the timely sharing of threat intelligence across ISACs and industry sectors can make the difference between early detection and widespread compromise. IsacChain enables the secure, verified sharing of indicators of compromise through blockchain technology, while simultaneously supporting automated NIS2 compliance for incident notification and risk management obligations. Discover how IsacChain can help your organization at www.isacchain.com