On 29 April 2026, four npm packages used by SAP developers, mbt and three @cap-js database packages, were published with a credential stealer that ran at install time. Researchers at Aikido, Wiz and Socket named the campaign "Mini Shai-Hulud" after the 2025 worm it imitates. The malware downloaded the Bun runtime, harvested GitHub, npm, cloud and Kubernetes credentials from developer machines and CI runners, encrypted them and pushed them to new public GitHub repositories under the victim's own account. Aikido's strongest lead for the first stolen token is an npm token exposed to pull request builds in SAP's CircleCI pipeline. Wiz attributes the campaign with high confidence to TeamPCP. The same code hit intercom-client and the PyPI package lightning the next day, and a later wave on 11 and 12 May reached the Mistral and OpenSearch npm clients. SAP published a security note for customers.
Key takeaways
- Malicious versions of
mbt1.2.48,@cap-js/sqlite2.2.2,@cap-js/postgres2.2.2 and@cap-js/db-service2.10.1 were live for hours on 29 April 2026. Socket said the packages have more than half a million weekly downloads combined. - Aikido traced a likely entry point to a pull request build in SAP's cloud-mta-build-tool repository whose CircleCI job had access to bot npm and GitHub tokens. This lead has not been confirmed by SAP.
- The payload stole GitHub, npm, cloud, Kubernetes and CI secrets, scraped GitHub Actions runner memory and tried to plant files in
.claudeand.vscodefolders of repositories it could reach. - GitGuardian later counted 971 public repositories created with stolen tokens across 23 GitHub accounts, after the campaign reached @mistralai/mistralai and @opensearch-project/opensearch in May 2026.
- The identity lesson: a publishing token that a pull request build can read belongs to whoever opens the pull request, and trusted publishing does not help if the CI job itself is running the attacker's code.
At a glance
| Organisations | SAP (cloud-mta-build-tool and Cloud Application Programming packages); developers and CI pipelines that installed them; later intercom-client, PyPI lightning, Mistral AI's and OpenSearch's npm clients |
|---|---|
| When | SAP packages poisoned and disclosed 29 April 2026; intercom-client and lightning 30 April 2026; Mistral and OpenSearch packages 11 to 12 May 2026 |
| Attacker | TeamPCP, according to Wiz (high confidence, based on a shared RSA key) and Socket |
| Entry point | Stolen publishing credentials; Aikido's strongest lead is an npm token exposed to a CircleCI pull request build in SAP's cloud-mta-build-tool repository |
| Identities abused | SAP bot npm and GitHub tokens (suspected), then victims' GitHub tokens, npm tokens, GitHub Actions secrets and OIDC publishing, and AWS, Azure, GCP and Kubernetes credentials |
| Impact | Credential-stealing versions of at least eight npm and PyPI packages; 971 public exfiltration repositories created with stolen tokens by 12 May 2026, according to GitGuardian |
| Category | NHI. Incident class: confirmed NHI breach (stolen publishing tokens used to spread a credential stealer; victims' tokens used for exfiltration) |
What happened
On the morning of 29 April 2026, a new version of mbt, SAP's Cloud MTA Build Tool, appeared on npm at 09:55 UTC. Over the next two hours three packages from SAP's Cloud Application Programming model followed: @cap-js/sqlite, @cap-js/postgres and @cap-js/db-service. Each had gained a preinstall script that ran setup.mjs, which downloaded the Bun JavaScript runtime and used it to run an 11.7 MB obfuscated payload. Timings Onapsis compiled from Socket's data show each version was detected within about eight minutes of publication and superseded by a clean release later that day.
Aikido's Raphael Silva found that the payload checked whether it was running in CI, quit on Russian-language systems and collected GitHub tokens, npm tokens, environment variables, GitHub Actions secrets and AWS, Azure, GCP and Kubernetes secrets, along with local files such as Claude and MCP configuration. On GitHub Actions runners it read the runner process's memory to recover masked secrets. It encrypted the results and committed them to new public repositories under the victim's account, and it used stolen GitHub Actions tokens to try to push .claude and .vscode files into other repositories under a commit author named "claude". Silva told Dark Reading that "earlier Shai-Hulud waves dumped secrets in the open, while this campaign encrypted the stolen data." Onapsis summed up the goal: "The primary goal of this malware is the automated theft of cloud credentials, service tokens, and private keys."
How the attacker got publishing rights is not confirmed. Aikido found that on 29 April a draft pull request titled "feat: ci speedup" was opened against SAP/cloud-mta-build-tool from a fork and closed within minutes. Its CircleCI build ran a commit that added the same loader and payload, and the job listed bot npm and GitHub token secrets. "This makes the CircleCI PR build the strongest lead for the initial credential theft," Aikido wrote. SAP told Dark Reading: "A security note is published and available for SAP customers and partners." Wiz "assesses with high confidence that this is the work of the same TeamPCP operators" seen in earlier supply chain compromises, based on a shared RSA public key used to encrypt stolen data. GitGuardian later noted the same RSA keys had been used in the Bitwarden CLI npm attack. On 30 April Wiz added intercom-client and the PyPI package lightning to the list.
The campaign did not stop there. GitGuardian reported on 12 May that a new phase targeting more than 300 packages had hit @mistralai/mistralai late on 11 May and @opensearch-project/opensearch early on 12 May, both removed within hours. It said most affected packages used trusted publishing, but because the malware ran inside CI it could use the pipeline's OIDC integration to publish anyway. By then 23 GitHub accounts had been used to create 971 public repositories holding encrypted stolen data. Our page on the GitHub internal repositories breach covers the TanStack and Nx Console compromises from the same period.
Timeline
| Date | Event |
|---|---|
| 29 April 2026 | A draft pull request against SAP/cloud-mta-build-tool triggers a CircleCI build with access to bot tokens, according to Aikido. |
| 29 April 2026 | Malicious mbt 1.2.48 is published at 09:55 UTC, followed by three @cap-js packages by 12:14 UTC; Aikido, Wiz and Onapsis publish analyses. |
| 30 April 2026 | Wiz reports intercom-client 7.0.5 and PyPI lightning 2.6.2 and 2.6.3 trojanised with the same code; SAP releases Security Note 3747787. |
| 11 May 2026 | A new wave compromises @mistralai/mistralai versions 2.2.2 to 2.2.4. |
| 12 May 2026 | @opensearch-project/opensearch is compromised; GitGuardian counts 971 exfiltration repositories created with stolen tokens. |
How it happened: the identity attack path
- Publishing token exposed to untrusted code. Aikido's evidence points to a CircleCI build that ran code from a fork's pull request while bot npm and GitHub tokens were available to the job.
- Trojanised releases. With publishing rights, the attacker released new versions of four SAP packages carrying a
preinstallhook. - Credentials harvested at install. Developer machines and CI runners that installed them handed over GitHub, npm, cloud and Kubernetes credentials, including masked secrets read from runner memory.
- Victims' tokens used against them. Stolen GitHub tokens created public repositories to hold the encrypted loot and pushed files into other repositories.
- Spread through CI publishing. Running inside release pipelines, the malware could repack packages and use OIDC trusted publishing, which is how later waves reached Mistral and OpenSearch packages.
Impact
- Confirmed: credential-stealing versions of four SAP npm packages on 29 April 2026, followed by intercom-client, PyPI lightning, @mistralai/mistralai and @opensearch-project/opensearch.
- Confirmed credential misuse: GitGuardian found 971 public repositories created with stolen GitHub tokens by 12 May 2026, and seven exposed tokens that were still valid when it published.
- Unknown: Socket told Dark Reading it had no reliable count of downloads of the malicious versions, so the number of affected developers and pipelines is not known.
- Potential: cloud, Kubernetes and CI access for anyone who installed an affected version. Wiz warned that "Even if your organization has not created any new repositories, your secrets may still be compromised".
What this means for NHI and AI agent security
Mini Shai-Hulud shows two weaknesses in how packages are published. The first is a long-lived publishing token reachable from pull request builds, which hands the token to anyone who can open a pull request. The second is subtler: trusted publishing removes stored tokens, but it trusts the pipeline. If attacker code runs inside a release job, the pipeline's own identity can publish for it. The payload's interest in Claude and MCP configuration files and its attempts to plant .claude files also show attackers treating AI coding tools as a place to persist and a store of credentials.
Defenders need to keep publishing identities away from untrusted code, scope release jobs tightly and watch what developer machines and agents can read. See our CI/CD Pipeline Identity Security Guide and AI Coding Agents Security Guide.
Recommendations
- Never expose publishing secrets to pull request builds. Configure CI so builds from forks get no secrets, and keep release credentials in a separate, protected job. See our CI/CD Pipeline Identity Security Guide.
- Rotate everything an affected install could reach. As Aikido's Silva put it, "Do not limit rotation to npm tokens"; include GitHub, cloud, Kubernetes, CI and local developer credentials. See the Leaked Credential Response Playbook.
- Lock down trusted publishing. Restrict OIDC publishing to a specific workflow, branch and environment with required reviewers, so injected code in another job cannot publish.
- Block install scripts where you can. Disable lifecycle scripts in CI by default and use a package firewall or cooldown for brand-new versions.
- Protect AI tool configuration. Review changes to
.claude,.vscodeand MCP configuration in repositories, and keep tokens out of agent configuration files. See our AI Coding Agents Security Guide. - Hunt for exfiltration repositories. Look for new public repositories in your organisation and commits containing the "OhNoWhatsGoingOnWithGitHub" marker that researchers documented.
Frequently asked questions
What is Mini Shai-Hulud?
Mini Shai-Hulud is a 2026 npm and PyPI supply chain campaign named after the 2025 Shai-Hulud worm. It first hit four SAP developer packages on 29 April 2026 with a Bun-based credential stealer that sends encrypted secrets to public GitHub repositories created with the victim's own token.
Which SAP packages were affected by Mini Shai-Hulud?
mbt 1.2.48, @cap-js/sqlite 2.2.2, @cap-js/postgres 2.2.2 and @cap-js/db-service 2.10.1, all published on 29 April 2026 and replaced the same day. SAP published Security Note 3747787 for customers.
Who is behind Mini Shai-Hulud?
Wiz assesses with high confidence that the TeamPCP group is responsible, based on a shared RSA key used to encrypt stolen data, and Socket also attributes it to TeamPCP. GitGuardian says the same keys appeared in the Bitwarden CLI npm attack. Wiz says it cannot link the campaign to the 2025 Shai-Hulud waves.
Related NHI Mgmt Group resources
GitHub Internal Repositories Breach 2026 · Miasma and Hades Worms 2026 · Bitwarden CLI npm Compromise 2026 · Shai-Hulud npm Worm, First Wave · CI/CD Pipeline Identity Security Guide
How NHI Mgmt Group can help
Publishing tokens, CI identities and the credentials on developer machines decide how far a poisoned package can travel. We help teams separate untrusted builds from release credentials, harden trusted publishing and plan rotation for the day a dependency turns hostile. See our NHI and AI agent security training.
References
- Aikido Security: Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer (29 April 2026)
- Wiz: Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware (29 April 2026)
- Onapsis: Emerging Supply Chain Attack ("Mini Shai-Hulud") Targeting SAP Cloud Application Programming Ecosystem (29 April 2026)
- Dark Reading: TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack (30 April 2026)
- GitGuardian: Mini Shai-Hulud: A persistent supply-chain worm (12 May 2026)