Skip to content
supplychainattack.orgSupply chain attack incident catalog
activehigh

Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware

A supply chain campaign dubbed "Mini Shai Hulud" targeted SAP npm packages with malicious versions containing credential-stealing malware. The campaign follows patterns similar to previous Shai-Hulud attacks.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
SAP ecosystem and npm users installing malicious packages
Ecosystems
Attack vectors
Threat actor
Affected entities
  • SAP npm packagesSpecific package names not disclosed in source text

A coordinated supply chain attack campaign, designated "Mini Shai Hulud," has targeted npm packages associated with SAP. The malicious packages were designed to steal credentials from affected users and systems.

The campaign appears to follow tactics and patterns from previous Shai-Hulud-style operations targeting supply chains. Wiz's analysis detected and documented the malicious npm packages linked to this campaign.

The specific package names, versions, and timeline details are referenced in the full Wiz security report. Organizations using SAP-related npm dependencies should review the detailed analysis for indicators of compromise and remediation guidance.

This incident highlights the continued risk of supply chain attacks targeting major enterprise software providers and their open-source ecosystems.

Remediation

  • Review npm package dependencies for SAP-related packages and check for suspicious versions
  • Audit supply chain security posture for npm packages using tools recommended by Wiz
  • Implement npm package signing verification and integrity checking
  • Monitor for lateral movement or credential theft indicators if potentially affected packages were installed
  • Follow Wiz's detailed remediation guidance available in their full security report

Sources

  1. Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware · Wiz

Cite this entry

"Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed April 29, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/supply-chain-campaign-targets-sap-npm-packages-with-credential-stealing-malware-1ghzqn

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in json-schema-inspector (npm)

    The npm package json-schema-inspector contained malicious code that performed remote code execution on installation. The package advertised itself as a JSON/XML schema validator but included a trigger routine that fetched and executed attacker-controlled payloads from a remote manifest.

    npmCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @yancyyu/agentcli (npm)

    The npm package @yancyyu/agentcli contains malicious code that extracts OAuth credentials and API keys for Lark/Feishu from the system keychain (macOS) and credential store (Windows), then exfiltrates them to a hardcoded remote IP address over plaintext HTTP. A persistent launchd agent ensures the exfiltration loop survives reboots.

    npmAI agents & skillsCompromised packageMalicious commit
  3. resolvedcritical

    Malicious code in app-sim-layer (npm)

    The npm package app-sim-layer contained malicious code in a postinstall hook that exfiltrated sensitive files (Solana keypairs, API keys, credentials), enumerated the user's filesystem, and on Linux granted remote SSH access to attacker infrastructure at 95.216.118.146.

    npmCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @crbrc/xbt (npm)

    The npm package @crbrc/xbt contains malicious code that exfiltrates OxaPay payment-gateway secrets and host metadata to a hardcoded attacker-controlled IP address, establishes a reverse TCP proxy tunnel, and allows remote process termination. The malicious behavior is conditionally activated only when all project source files import the companion package @crb/xbr.

    npmCompromised packageMalicious commit