Intel Node

SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware

lowmalware2026-04-29T16:26:00+00:00
malwarecloud

Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the mini Shai-Hulud – has affected the following packages associated with SAP's JavaScript and cloud application

View Source