"A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages

Source: Snyk Security Blog  ·  Category: Supply Chain


Four SAP-ecosystem npm packages compromised by 'Mini Shai-Hulud' stealer on April 29, 2026. Law firms using SAP development tools or dependencies must audit npm package dependencies immediately and rotate credentials; client data exposure possible if SAP systems process sensitive matter information.

→ Read the full article

Read more