Briefing

Mini Shai-Hulud Campaign Targets SAP-Related npm Packages with Credential-Stealing Malware

security
by [email protected] (The Hacker News) ·

Patch affected npm packages, tighten dependency management, and monitor for credential theft.

What to do now

Patch affected npm packages, tighten dependency management, and monitor for credential theft.

Summary

Cybersecurity researchers have identified a new supply chain attack campaign dubbed Mini Shai‑Hulud that targets SAP‑related npm packages. The campaign, coordinated by Aikido Security, Onapsis, OX Security, SafeDep, Socket, StepSecurity, and Google‑owned Wiz, injects credential‑stealing malware into vulnerable packages. Affected packages include those frequently used in SAP integrations, exposing developers to credential theft and potential lateral movement. The attackers leverage malicious code to harvest usernames, passwords, and API tokens from compromised environments. The campaign demonstrates the growing sophistication of supply chain attacks against enterprise software ecosystems. Researchers recommend immediate patching of affected npm packages and tightening of dependency management. The incident serves as a reminder of the critical need for secure package sourcing and runtime monitoring. SAP customers and developers should verify package integrity and update to the latest secure versions.

Key changes

  • Mini Shai‑Hulud campaign targets SAP‑related npm packages.
  • Attack injects credential‑stealing malware into vulnerable packages.
  • Affected packages are widely used in SAP integrations.
  • Malware harvests usernames, passwords, and API tokens.
  • Researchers identified campaign by Aikido Security, Onapsis, OX Security, SafeDep, Socket, StepSecurity, and Google‑owned Wiz.
  • Immediate patching of affected npm packages is recommended.
  • Tightening of dependency management is advised.
  • Incident underscores need for secure package sourcing and runtime monitoring.

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting