Skip to content
supplychainattack.orgSupply chain attack incident catalog
activehigh

A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages

StepSecurity identified an npm supply chain attack campaign targeting SAP-ecosystem packages using preinstall hooks to download and execute an obfuscated Bun runtime payload. At least two SAP-related npm packages have been confirmed compromised in this active campaign.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
SAP ecosystem; npm-dependent applications
Ecosystems
Attack vectors
Threat actor
Affected entities
  • SAP-related npm packagesAt least two packages confirmed compromised

StepSecurity has detected an active npm supply chain attack campaign exploiting preinstall hooks in npm packages. The attack mechanism involves downloading the Bun JavaScript runtime and executing an 11 MB obfuscated payload during package installation.

The campaign has specifically targeted packages in the SAP ecosystem, with at least two SAP-related npm packages confirmed as compromised so far. The use of obfuscated payloads and runtime downloads suggests an attempt to evade static detection and analysis tools.

This attack leverages a common npm installation hook to execute arbitrary code on developer machines and build systems that install the affected packages, potentially affecting any downstream consumers of these packages.

Indicators of compromise

Packages
  • <UNKNOWN>

Remediation

  • Audit npm package installations and preinstall hooks for suspicious activity
  • Review and update SAP-related npm dependencies to patched versions once available
  • Inspect package-lock.json and node_modules for unauthorized Bun runtime downloads
  • Monitor for and block execution of unverified Bun runtime binaries in build and development environments
  • Enable strict npm audit scanning and consider using lock file integrity verification
  • Check npm audit logs and installation history for affected packages

Sources

  1. A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages · StepSecurity

Cite this entry

"A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 4, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/a-mini-shai-hulud-has-appeared-obfuscated-bun-runtime-payloads-hit-sap-related-n-1ec9xf

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malware in eth-codergen

    Malware was discovered in the npm package eth-codergen. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package
  2. containedcritical

    Malware in fs-extra-core

    Malware was discovered in the npm package fs-extra-core. Systems with this package installed or running are considered fully compromised and require immediate remediation including secret rotation and package removal.

    npmCompromised package
  3. containedcritical

    Malware in cktool-core

    Malware was discovered in the npm package cktool-core. Systems with the package installed or running are considered fully compromised and require immediate remediation.

    npmCompromised package
  4. activecritical

    Malware in lychee-norm-cache

    Malware discovered in the npm package lychee-norm-cache. Systems with this package installed are considered fully compromised and require immediate remediation.

    npmCompromised package