Security researchers report that a supply-chain attack campaign dubbed “Mini Shai-Hulud” compromises multiple npm packages used in SAP-related development ecosystems. Coverage from several firms—including Aikido Security, Onapsis, OX Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz—describes the campaign as using malicious code in distributed packages to steal credentials from affected systems or users. The Register and Dark Reading report that the compromised packages include those related to SAP cloud application development tooling, and other developer-focused ecosystems were also targeted as the campaign expanded. The Register additionally states that other npm packages—such as those used by Intercom-related development workflows—are implicated, alongside a “wave” of supply-chain infections observed across common software repositories. The Hacker News frames the issue as SAP-related npm packages being hit by a credential-stealing campaign and notes the involvement of multiple independent research teams in identifying impacted packages and behavior. The reporting emphasizes that the compromised packages are part of the normal npm distribution channel, making detection and remediation dependent on identifying which package versions are affected and replacing or removing them.
Mini Shai-Hulud supply-chain attack compromises SAP npm packages with credential-stealing malware
Security researchers report that a supply-chain attack campaign dubbed “Mini Shai-Hulud” compromises multiple npm packages used in SAP-related development ecosystems. Coverage from several firms—inclu...
- Researchers describe a supply-chain attack campaign called “Mini Shai-Hulud.”
- The campaign compromises npm packages associated with SAP-related development tooling.
- The malicious activity is described as credential-stealing malware.
- Multiple security firms report findings, including Aikido Security, Onapsis, and Google-owned Wiz.
- Reporting indicates the campaign expands beyond SAP, with other developer tools/ecosystems also affected.
Mini Shai-Hulud caught spreading credential-stealing malware The wave of supply chain attacks aimed at security and developer tools has washed up more victims, namely SAP and Intercom npm packages, plus the lightning PyPI package.…
3 months agoSeveral npm packages for SAP's cloud application development ecosystem have been compromised as TeamPCP's supply chain attacks broaden.
3 months agoCybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, Onapsis, OX Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the Mini Shai-Hulud – has affected the following packages associated with
3 months ago
Meta agrees up to $18 billion settlement over alleged harms to young social media users
Meta agrees to a landmark legal settlement in the United States after lawsuits alleging its Facebook and Instagram platf...
Andreessen Horowitz Raises $1.1 Billion for AI Infrastructure “Machine Age” Fund
Andreessen Horowitz says it has raised $1.1 billion for a new artificial intelligence infrastructure fund. Bloomberg rep...
Visa expands cybersecurity support for clients and payments industry amid AI-era threats
Visa announces expanded support for its clients and the wider payments industry as organisations adapt to a new AI-drive...