Compromise of SAP-Related npm Packages in Credential Theft Attack

A recent supply chain attack has targeted npm packages linked to SAP, introducing malware designed to steal user credentials.

3 min readCybersecurity

Recent findings from cybersecurity experts have revealed a concerning supply chain attack that has compromised npm packages associated with SAP. This malicious campaign, dubbed mini Shai-Hulud, has been identified by several security firms, including Aikido Security, SafeDep, Socket, StepSecurity, and Wiz, which is owned by Google. The attack focuses on packages that are integral to SAP's JavaScript and cloud applications, raising alarms about the potential for widespread credential theft. The malware embedded within these packages poses a significant risk to users, as it is designed to capture sensitive login information. Organizations utilizing these npm packages are urged to review their dependencies and take appropriate measures to mitigate the risks posed by this attack. The ongoing threat highlights the vulnerabilities present in software supply chains and the need for enhanced security protocols to protect against such incidents.

Cybersecurity