CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1299

As cited

Copy frozen at (site build).

threat intel

Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware

Security researchers identified malicious npm packages associated with a supply chain campaign targeting SAP environments, distributing credential-stealing malware. The campaign, termed Mini Shai Hulud, represents an evolution of previous supply chain attack tactics focusing on development dependency chains.

Why it matters: SAP customers and developers who use npm packages in their build pipelines face direct risk of credential compromise and lateral movement into production environments; practitioners should audit npm dependencies and implement package verification controls immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware

Security researchers identified malicious npm packages associated with a supply chain campaign targeting SAP environments, distributing credential-stealing malware. The campaign, termed Mini Shai Hulud, represents an evolution of previous supply chain attack tactics focusing on development dependency chains.

Why it matters: SAP customers and developers who use npm packages in their build pipelines face direct risk of credential compromise and lateral movement into production environments; practitioners should audit npm dependencies and implement package verification controls immediately.

VendorsSAP
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary