SAP npm Supply Chain Attack 2026: Credentials Stolen
Four SAP npm packages were quietly backdoored on April 29, 2026, in a supply chain attack that stole GitHub tokens, AWS credentials, and browser passwords from enterprise developers. The SAP npm supply chain attack, dubbed Mini Shai-Hulud by threat actor TeamPCP, affected over 2.25 million monthly downloads in a four-hour window. If your team ran npm install that day, your credentials may already be compromised.
SAP npm Supply Chain Attack 2026: Credentials Stolen Read More ยป
