ctipilot.chSwitzerland · Europe · Public sector

Mini Shai-Hulud — TeamPCP SAP CAP npm supply-chain worm

campaign · campaign:mini-shai-hulud

Coverage timeline
1
first 2026-05-06 → last 2026-05-06
Briefs
1
1 distinct
Sources cited
3
3 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence

Story timeline

  1. 2026-05-06CTI Daily Brief — 2026-05-06
    researchFirst coverage. Four malicious SAP CAP npm packages published 2026-04-29; ~1,800 GitHub repos compromised within hours; self-propagating via stolen npm tokens; exfiltration via victim-owned GitHub repos.

Where this entity is cited

  • research1

Source distribution

  • isc.sans.edu1 (33%)
  • research.checkpoint.com1 (33%)
  • sophos.com1 (33%)

Items in briefs about Mini Shai-Hulud — TeamPCP SAP CAP npm supply-chain worm

No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.