Experts say supply chain attacks compromised SAP and Intercom npm packages, plus the PyPI package Lightning, in a campaign that calls itself Mini Shai-Hulud (Jessica Lyons/The Register)

A coordinated supply chain attack campaign called 'Mini Shai-Hulud' has successfully compromised critical dependencies across multiple ecosystems—including SAP npm packages, PyPI's Lightning library, and Intercom—enabling threat actors to steal developer credentials and CI/CD secrets from approximately 1,800 organizations. This attack demonstrates a critical vulnerability in how modern software relies on transitive dependencies, with a single compromised package triggering cascading compromises across the supply chain. IT organizations face immediate risk to cloud credentials (AWS/Azure/GCP), Kubernetes access, and developer secrets stored in CI/CD pipelines.

Jessica LyonsTechMeme2 min read
Read full article
Experts say supply chain attacks compromised SAP and Intercom npm packages, plus the PyPI package Lightning, in a campaign that calls itself Mini Shai-Hulud (Jessica Lyons/The Register)
Jessica Lyons / The Register: Experts say supply chain attacks compromised SAP and Intercom npm packages, plus the PyPI package Lightning, in a campaign that calls itself Mini Shai-Hulud — The wave of supply chain attacks aimed at security and developer tools has washed up more victims, namely SAP and Intercom npm packages, plus the lightning PyPI package.