WeSearch

The never-ending supply chain attacks worm into SAP npm packages, other dev tools

·5 min read · 0 reactions · 0 comments · 3 views
#supply chain attack#npm#malware#cybersecurity#credential theft#SAP#Intercom#Wiz#Socket#TeamPCP#Checkmarx#Bitwarden#Telnyx
The never-ending supply chain attacks worm into SAP npm packages, other dev tools
⚡ TL;DR · AI summary

Multiple npm and PyPI packages, including those from SAP, Intercom, and lightning, have been compromised in a supply chain attack linked to the Mini Shai-Hulud worm. The malicious packages contain credential-stealing malware and are tied to the cybercrime group TeamPCP. The attack mirrors earlier incidents involving Checkmarx, Bitwarden, and other developer tools, with security firms Wiz and Socket identifying the same malicious code across the affected packages.

Key facts
Original article
The Register
Read full at The Register →
Opening excerpt (first ~120 words) tap to expand

Security The never-ending supply chain attacks worm into SAP npm packages, other dev tools Mini Shai-Hulud caught spreading credential-stealing malware Jessica Lyons Thu 30 Apr 2026 // 23:21 UTC The wave of supply chain attacks aimed at security and developer tools has washed up more victims, namely SAP and Intercom npm packages, plus the lightning PyPI package. The newly compromised packages as of Thursday include [email protected] (according to Google-owned Wiz) and [email protected] (says supply-chain security firm Socket) and [email protected] and 2.6.3. Attackers infected all versions with the same credential-stealing malware that, on Wednesday, poisoned multiple npm packages associated with SAP's JavaScript and cloud application development ecosystem.

Excerpt limited to ~120 words for fair-use compliance. The full article is at The Register.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from The Register