Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SAP npm Packages Exploited in Major Credential Theft

SAP npm Packages Exploited in Major Credential Theft

Posted on May 4, 2026 By CWS

A recent cyberattack has targeted the SAP developer community by compromising npm packages, posing a serious threat to developer credentials and cloud services. This sophisticated supply chain attack employs a malicious worm named ‘Mini Shai-Hulud’ to silently steal sensitive information from affected systems.

Worm Infiltrates SAP Ecosystem

The attack impacts four official SAP packages: mbt, @cap-js/sqlite, @cap-js/postgres, and @cap-js/db-service. When developers or CI pipelines execute the npm install command on these compromised packages, a hidden script activates before the installation is complete. This preinstall script downloads the Bun JavaScript runtime and executes an obfuscated payload to harvest credentials.

Mini Shai-Hulud appears to be an evolution of the Shai-Hulud worm, first identified in 2025. Analysts from Endor Labs discovered that this new variant utilizes the same Bun runtime version 1.3.13 and similar encryption methods as its predecessor, confirming the involvement of the same threat actors targeting SAP’s developer ecosystem.

Credential Harvesting Techniques

Upon execution, the payload deploys five distinct credential harvesters. The first focuses on npm tokens, scanning various configuration files and validating them against the npm registry. This ensures only publish-capable tokens are replicated.

Subsequent harvesters target GitHub and cloud credentials, accessing sensitive data stored in-memory and in configuration files across platforms like AWS, Google Cloud, and Azure. The worm also seeks out credentials from AI coding tools, scrutinizing project settings and configuration files for popular tools like VS Code and Claude Code.

Mitigation and Future Defense

Developers who suspect their systems were compromised should treat all credentials as exposed and take immediate action. This includes uninstalling affected packages, reinstalling clean versions with the –ignore-scripts flag, and thoroughly auditing systems for suspicious files.

For long-term security, it’s crucial to restrict npm OpenID Connect (OIDC) trusted publishing to specific workflows and enforce the –ignore-scripts option in CI environments. While reactive measures can help, proactive auditing and prompt detection are essential to mitigate future risks.

Overall, this attack highlights the critical need for vigilance and robust security practices within the software development lifecycle, particularly in managing dependencies and securing credentials.

Cyber Security News Tags:AI tools, Bun runtime, CAP applications, cloud security, credential theft, Cybersecurity, dependency security, developer ecosystem, Endor Labs, GitHub, malware analysis, NPM, SAP, Shai-Hulud worm, supply chain attack

Post navigation

Previous Post: Cisco Acquires Astrix Security for Non-Human Identity Protection
Next Post: Linux Zero-Day Vulnerability Urges Immediate Patching

Related Posts

Ransomware Targeting Hyper-V and VMware ESXi Surges as Akira Group Exploits System Vulnerabilities Ransomware Targeting Hyper-V and VMware ESXi Surges as Akira Group Exploits System Vulnerabilities Cyber Security News
Hackers Compromise Intelligence Website Used by CIA and Other Agencies Hackers Compromise Intelligence Website Used by CIA and Other Agencies Cyber Security News
MCP Servers Found with Thousands of Security Flaws MCP Servers Found with Thousands of Security Flaws Cyber Security News
Hackers Target Developers with Fake Job Interviews Hackers Target Developers with Fake Job Interviews Cyber Security News
Malicious AI Extension Hijacks Search Data Malicious AI Extension Hijacks Search Data Cyber Security News
Exploited Microsoft SharePoint Flaws Risk RCE and Data Breaches Exploited Microsoft SharePoint Flaws Risk RCE and Data Breaches Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Android RAT Threat Poses as Emergency App
  • Critical VeloCloud Vulnerability Actively Exploited
  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT
  • Malware Exploits Google Passkey Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Android RAT Threat Poses as Emergency App
  • Critical VeloCloud Vulnerability Actively Exploited
  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT
  • Malware Exploits Google Passkey Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark