PULSE NAME
Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware
WHITE TeamPCP AlienVault 2026-04-30 Modified: 2026-04-30
30
IOCs
MEDIUM VOLUME
A supply chain operation dubbed 'Mini Shai Hulud' compromised SAP-related npm packages by injecting malicious preinstall scripts that execute during installation. The campaign leverages multi-stage payloads to harvest developer and CI/CD secrets from GitHub, npm, and major cloud providers, exfiltrating data via attacker-controlled GitHub repositories. Malicious versions of legitimate SAP ecosystem packages execute obfuscated payloads that collect GitHub tokens, npm credentials, cloud secrets from AWS, Azure and GCP, Kubernetes tokens, and GitHub Actions secrets. The malware includes propagation logic to infect additional repositories and features browser credential theft capabilities. It performs language checks to avoid Russian-speaking systems. Attribution points to TeamPCP based on shared RSA public keys and overlapping techniques from previous operations.
Indicators of Compromise (10 / 30 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0af7415d65753f6aede8c9c0f39be478666b9c12 2026-04-30
FileHash-SHA1 307d0fa7407d40e67d14e9d5a4c61ac5b4f20431 2026-04-30
FileHash-SHA1 4b04304f6d51392e3f43856c94ca95800518a694 2026-04-30
FileHash-SHA1 6bc859aaee1f8885eec2a3016226e877e5adba08 2026-04-30
FileHash-SHA1 7b0278216ac31ec18eca9eb8bc1c1261a1b26f6c 2026-04-30
FileHash-SHA1 7b6a28e92149637e5d7c7f4a2d3e54acd507c929 2026-04-30
FileHash-SHA1 bc95cc5dda788295aa0c9456791520599ef99526 2026-04-30
FileHash-SHA1 ca4a5bb85778ffcd2153ace88fe2d882c8ceeb23 2026-04-30
FileHash-SHA1 e80824a19f48d778a746571bb15279b5679fd61c 2026-04-30
FileHash-SHA1 ff7ed7a0fa1c43eed01809d076feedbaed464fc7 2026-04-30