SAP Cloud Build Tool Packaged A Mini Shai-Hulud Malicious Dependency That Uses Bun
Blog post from Semgrep
A recent coordinated npm supply chain attack has targeted packages within the SAP development ecosystem, notably affecting mbt, @cap-js/sqlite, @cap-js/postgres, and @cap-js/db-service. The attackers employed preinstall hooks to deploy a malicious payload through the Bun JavaScript runtime, leading to credential theft from developer machines, indicated by the creation of GitHub repositories with the description "A Mini Shai-Hulud has Appeared." Semgrep has issued an advisory and rules to help check for these compromised packages, urging users to scan projects for the presence of these dependencies and advising on further remediation steps if detected. The attack primarily focuses on stealing a variety of secrets, including GitHub tokens and cloud service secrets, by exfiltrating data encrypted with AES-256-GCM and stored in specific file paths. Users are advised to rotate secrets widely and review GitHub activity for any signs of unauthorized access or data exfiltration.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 6 | 1,821 | 338 | 111 | +22% |
| Kubernetes | 2 | 2,306 | 381 | 103 | +25% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.