Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware

Reported 30 Apr 2026 by otx · Severity: medium

A supply chain operation dubbed 'Mini Shai Hulud' compromised SAP-related npm packages by injecting malicious preinstall scripts that execute during installation. The campaign leverages multi-stage payloads to harvest developer and CI/CD secrets from GitHub, npm, and major cloud