Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Mini Shai-Hulud: npm Worm Hits SAP Developer Packages

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Kiran Raj
Word Count
2,926
Company Posts That Month
35
Language
English
Hacker News Points
-
Post removed?
No
Summary

A new npm supply chain attack has targeted the SAP developer ecosystem by exploiting vulnerabilities in four vital packages: mbt, @cap-js/sqlite, @cap-js/postgres, and @cap-js/db-service. The attack follows a two-stage methodology similar to the Shai-Hulud worm, downloading the Bun JavaScript runtime to execute an 11.7 MB obfuscated payload that harvests credentials like GitHub tokens, cloud service credentials, and AI coding tool configurations. The compromised packages were distributed using stolen npm tokens and a misconfigured GitHub OIDC workflow, allowing the attacker to publish malicious versions without detection. The attack leveraged GitHub repositories as command and control (C2) for exfiltrated data, with each machine that installed the compromised packages potentially acting as a propagation point for the malware. In response, affected developers are advised to uninstall the malicious packages, rotate all exposed credentials, and review their publishing and security configurations to prevent future incidents. The swift publication and takedown of these malicious packages highlight the need for proactive security measures, such as runtime controls and strict token policies, to mitigate the risks of such sophisticated supply chain attacks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 13 1,821 338 111 +22%
Kubernetes 3 2,306 381 103 +25%
MCP 2 6,108 613 170 +36%
AI Coding Assistant 1 1,480 382 153 +18%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.