Security researchers report that a supply-chain attack campaign dubbed “Mini Shai-Hulud” compromises multiple npm packages used in SAP-related development ecosystems. Coverage from several firms—including Aikido Security, Onapsis, OX Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz—describes the campaign as using malicious code in distributed packages to steal credentials from affected systems or users. The Register and Dark Reading report that the compromised packages include those related to SAP cloud application development tooling, and other developer-focused ecosystems were also targeted as the campaign expanded. The Register additionally states that other npm packages—such as those used by Intercom-related development workflows—are implicated, alongside a “wave” of supply-chain infections observed across common software repositories. The Hacker News frames the issue as SAP-related npm packages being hit by a credential-stealing campaign and notes the involvement of multiple independent research teams in identifying impacted packages and behavior. The reporting emphasizes that the compromised packages are part of the normal npm distribution channel, making detection and remediation dependent on identifying which package versions are affected and replacing or removing them.