Mini Shai-Hulud: npm Worm Hits SAP Developer Packages
Blog post from Endor Labs
A new npm supply chain attack has targeted the SAP developer ecosystem by exploiting vulnerabilities in four vital packages: mbt, @cap-js/sqlite, @cap-js/postgres, and @cap-js/db-service. The attack follows a two-stage methodology similar to the Shai-Hulud worm, downloading the Bun JavaScript runtime to execute an 11.7 MB obfuscated payload that harvests credentials like GitHub tokens, cloud service credentials, and AI coding tool configurations. The compromised packages were distributed using stolen npm tokens and a misconfigured GitHub OIDC workflow, allowing the attacker to publish malicious versions without detection. The attack leveraged GitHub repositories as command and control (C2) for exfiltrated data, with each machine that installed the compromised packages potentially acting as a propagation point for the malware. In response, affected developers are advised to uninstall the malicious packages, rotate all exposed credentials, and review their publishing and security configurations to prevent future incidents. The swift publication and takedown of these malicious packages highlight the need for proactive security measures, such as runtime controls and strict token policies, to mitigate the risks of such sophisticated supply chain attacks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 13 | 1,821 | 338 | 111 | +22% |
| Kubernetes | 3 | 2,306 | 381 | 103 | +25% |
| MCP | 2 | 6,108 | 613 | 170 | +36% |
| AI Coding Assistant | 1 | 1,480 | 382 | 153 | +18% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.