Cracked npm logo leaking stolen credentials from compromised SAP CAP packages in the Mini Shai-Hulud supply chain attack April 2026

SAP npm Supply Chain Attack 2026: Credentials Stolen

Four SAP npm packages were quietly backdoored on April 29, 2026, in a supply chain attack that stole GitHub tokens, AWS credentials, and browser passwords from enterprise developers. The SAP npm supply chain attack, dubbed Mini Shai-Hulud by threat actor TeamPCP, affected over 2.25 million monthly downloads in a four-hour window. If your team ran npm install that day, your credentials may already be compromised.

SAP npm Supply Chain Attack 2026: Credentials Stolen Read More ยป