PULSE NAME
Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware
WHITE TeamPCP AlienVault 2026-04-30 Modified: 2026-04-30
30
IOCs
MEDIUM VOLUME
A supply chain operation dubbed 'Mini Shai Hulud' compromised SAP-related npm packages by injecting malicious preinstall scripts that execute during installation. The campaign leverages multi-stage payloads to harvest developer and CI/CD secrets from GitHub, npm, and major cloud providers, exfiltrating data via attacker-controlled GitHub repositories. Malicious versions of legitimate SAP ecosystem packages execute obfuscated payloads that collect GitHub tokens, npm credentials, cloud secrets from AWS, Azure and GCP, Kubernetes tokens, and GitHub Actions secrets. The malware includes propagation logic to infect additional repositories and features browser credential theft capabilities. It performs language checks to avoid Russian-speaking systems. Attribution points to TeamPCP based on shared RSA public keys and overlapping techniques from previous operations.
Indicators of Compromise (10 / 30 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 00ca0c04d247ef09f2b2acc452029345 2026-04-30
FileHash-MD5 04d8a99447b16f6839fff3b978f88d7e 2026-04-30
FileHash-MD5 35baf8316645372eea40b91d48acb067 2026-04-30
FileHash-MD5 45dc9c02f82b4370ca92785282d43a86 2026-04-30
FileHash-MD5 6fb87d243b011b5445f379f80e1a6b4d 2026-04-30
FileHash-MD5 8cd683f78735c9bfc32600c73d3d9abe 2026-04-30
FileHash-MD5 b523a69b27064d1715d1f0aaffcfae63 2026-04-30
FileHash-MD5 d468f16eafccbc54a994f3d675ace8ae 2026-04-30
FileHash-MD5 dbb9b09957113463bbeb420c2c4108b5 2026-04-30
FileHash-MD5 e32eaf0c3cde9616831a1e92d42b0058 2026-04-30