External Publication
Visit Post

SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack

The Hacker News | #1 Trusted Source for Cybersecurity News [Uno… April 29, 2026
Source
Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the mini Shai-Hulud – has affected the following packages associated with SAP's JavaScript and cloud application

Discussion in the ATmosphere

Loading comments...