Vulnerabilities · 137 days ago
A trusted dependency can become an execution point before your build ever starts. In this campaign, the danger is not just a bad package version. It is that a preinstall script can pull in Bun and run a credential stealer during dependency installation, before normal package integrity checks help you.
Researchers say TeamPCP’s “Mini Shai-Hulud” campaign hit SAP CAP-related npm packages and spread to other ecosystems. The affected releases include mbt@1.2.48, @cap-js/db-service@2.10.1, @cap-js/postgres@2.2.2, @cap-js/sqlite@2.2.2, intercom-client@7.0.4 and 7.0.5, and lightning@2.6.2 and 2.6.3 on PyPI. The malware targets developer and CI/CD secrets, including GitHub, npm, cloud, and Kubernetes credentials, and uses compromised tokens to propagate.
The forward risk is broader than the initial package set. Any pipeline that installs these dependencies may have exposed tokens already, and those secrets can outlive the package cleanup if they were reused elsewhere.
9 sources covering this story
1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom
The compromised Lightning and Intercom packages have a combined monthly download count of nearly 10 million.
Ongoing supply chain attacks worm into SAP npm packages
: Mini Shai-Hulud caught spreading credential-stealing malware
Ongoing supply chain attacks worm into SAP npm packages
: Mini Shai-Hulud caught spreading credential-stealing malware
Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP...
Socket found a malicious Intercom PHP package on Packagist using Composer plugin execution to steal credentials and spread across ecosystems.
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
Several npm packages for SAP's cloud application development ecosystem have been compromised as TeamPCP's supply chain attacks broaden.
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulu...
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
SAP NPM Packages Targeted in Supply Chain Attack
The Mini Shai-Hulud attack introduced a preinstall hook to fetch and execute a Bun binary and bypass security monitoring.
Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin
intercom/intercom-php 5.0.2 was compromised and converted into a Composer plugin that exfiltrates credentials at install time, extending the Mini Shai-Hulud campaign to PHP.
SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack
SAP npm packages poisoned on April 29, 2026 + AES-256-GCM encrypted credential theft + AI coding tools abused for spread.
Official SAP npm packages compromised to steal credentials
Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal credentials and authentication tokens from developers' systems.
Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware | Wiz Blog
Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign - Mini Shai Hulud.
TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MT...
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environ...
Part of the PlainSec briefing for 2026-05-02