A Mini Shai-Hulud Targeting the SAP Ecosystem
Blog post from GitGuardian
Aikido researchers have identified an ongoing malware attack involving compromised Node.js packages within SAP's namespace, characterized by its ability to adapt to Continuous Integration (CI) environments and exfiltrate GitHub personal access tokens. This attack, reminiscent of recent supply-chain breaches, involves the malware reading CI environment variables to modify its behavior, exfiltrating encrypted secrets using discovered GitHub tokens, and employing a fallback mechanism that decodes specially crafted commit messages if tokens are absent. The exfiltrated data is encrypted using RSA keys, consistent with those from a previous attack on @bitwarden/cli. GitGuardian found seven commits with exposed tokens, which remain active, allowing the attacker to create public repositories with Dune-themed names, housing encrypted payloads within JSON files. The campaign involves 23 GitHub accounts and 971 public repositories, with a significant concentration of activity linked to six accounts responsible for 96% of the repositories, demonstrating the attack's extensive reach and the potential for further growth.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 3 | 1,821 | 338 | 111 | +22% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.