[Action required] SAP npm packages compromised 
Advisory

“A Mini Shai-Hulud Has Appeared”: When the npm Supply Chain Reaches Into SAP

 

On 29 April 2026, four official npm packages from the SAP development ecosystem were published in malicious versions. For roughly two to four hours that day, anyone running npm install against the wrong version pulled a credential-stealing payload straight into their developer workstation or CI/CD pipeline. The campaign, which researchers are calling “Mini Shai-Hulud”, marks the first time the Shai-Hulud worm family has reached directly into the SAP supply chain and it is a signal worth paying attention to.

See https://securitybridge.com/blog/a-mini-shai-hulud-has-appeared-when-the-npm-supply-chain-reaches-into-sap/ for more details.

  • Share with: