DAPSSADAPSSA

SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack

By DAPSSA AI Desk | 2026-04-30T05:43:53.065Z
SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack

Overview

Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the mini Shai-Hulud – has affected the following packages associated with SAP's JavaScript and cloud application

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/04/sap-npm-packages-compromised-by-mini.html

Join the Discussion