# TeamPCP Mini Shai-Hulud attack compromises SAP npm packages

**Published:** 2026-07-18T01:09:47.806Z  
**Topic:** Injective  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/27959335-3ed2-40ba-9b6e-5e0a06e1391b

TeamPCP supply chain attack hits four SAP npm packages with over 500,000 weekly downloads, exposing developer and cloud credentials.

The malicious “Mini Shai‑Hulud” campaign compromised four SAP Cloud Application Programming Model (CAP) and MBT npm packages on Wednesday, injecting pre‑install scripts that harvest GitHub, npm and cloud credentials [1].  

| At a glance | |
|---|---|
| Packages compromised | @cap-js/sqlite v2.2.2, @cap-js/postgres v2.2.2, @cap-js/db‑service v2.10.1, mbt v1.2.48 |
| Weekly downloads | > 500,000 aggregate downloads across the four packages |
| Date of release | Wednesday (week of May 1, 2024) |
| Catalyst | TeamPCP supply‑chain attack using “Mini Shai‑Hulud” payload [1] |

## Scope and mechanics of the attack  
The four npm packages, core to SAP’s cloud deployment workflows, were published with malicious pre‑install scripts that execute automatically when the dependency is installed. Researchers at Wiz, Socket and Aikido Security traced the campaign to the cyber‑crime group TeamPCP, noting technical overlaps with its prior compromises of Trivy and KICS [1]. The payloads collect a range of secrets—including GitHub tokens, npm credentials, Kubernetes and CI/CD keys—and exfiltrate the data to attacker‑controlled GitHub repositories. Unlike earlier “Shai‑Hulud” waves that dumped secrets openly, this campaign encrypts the stolen data before exfiltration [1].

## Potential impact on the SAP ecosystem  
Socket estimates the affected packages receive more than half a million downloads each week, meaning a single compromised install can expose developer machines or CI pipelines that hold privileged access to GitHub, npm and major cloud providers [1]. SAP responded by publishing a security note for customers and partners, but the rapid takedown of the poisoned packages leaves a window of exposure that may already have been exploited [1]. Aikido’s Raphael Silva warns that the fallout could be extensive, as stolen credentials can be reused to compromise downstream repositories and enterprise environments [1].

## Broader supply‑chain context  
TeamPCP’s approach mirrors a growing trend of multi‑stage supply‑chain attacks that first steal publishing credentials, then use them to inject malicious code into high‑value packages. Similar tactics have recently appeared in attacks on the lightning PyPI package and Intercom’s npm SDK, suggesting the group is expanding across ecosystems [1]. While the exact initial breach vector for the SAP packages remains unconfirmed, a misconfigured CircleCI token in the mbt repository is a leading hypothesis [1].

## What to watch  
- Monitor for any of the four compromised package versions in lockfiles, internal registries or CI logs; immediate secret rotation is advised if found [1].  
- Watch for further disclosures from SAP or downstream vendors about additional compromised artifacts or credential misuse.  
- Track upcoming npm security changes, such as the planned v12 defaults that block install scripts and external Git dependencies, which could mitigate similar attacks in the future [2].

The Mini Shai‑Hulud incident underscores the heightened risk to enterprise software supply chains when high‑profile, widely used packages are targeted, and it raises questions about how quickly organizations can detect and remediate credential theft across complex CI/CD environments.

## Sources
1. Dark Reading — [TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack](https://www.darkreading.com/cloud-security/teampcp-sap-packages-mini-shai-hulud)
2. Infosecurity-magazine.com — [GitHub to Update npm to Thwart Software Supply Chain Attacks](https://www.infosecurity-magazine.com/news/github-update-npm-supply-chain/)

---
Cite as: TrendWatcher, "TeamPCP Mini Shai-Hulud attack compromises SAP npm packages", https://www.trendwatcher.in/article/27959335-3ed2-40ba-9b6e-5e0a06e1391b
