Multiple npm package incidents exposed developers and CI/CD pipelines to supply-chain risk, including suspicious SAP CAP-related packages and a malicious brand-squatting package impersonating TanStack. Socket reported that affected versions of mbt and several @cap-js/* packages introduced a new preinstall script that downloaded a platform-specific Bun archive from GitHub Releases, extracted it, and executed the binary during installation. The behavior was flagged as high risk because the packages had not previously depended on Bun, the installer reportedly followed HTTP redirects without validating the destination, and Windows execution used PowerShell with -ExecutionPolicy Bypass, creating an unexpected code-execution path in SAP development and deployment workflows.
In a separate but concurrent npm attack, the unscoped tanstack package was used to impersonate the legitimate @tanstack/* ecosystem and steal secrets from developer machines. Malicious versions 2.0.4 through 2.0.7, published by maintainer sh20raj, used postinstall scripts to exfiltrate .env and related files to an attacker-controlled Svix endpoint at api.svix.com, potentially exposing API keys, database credentials, and authentication tokens. TanStack maintainer Tanner Linsley said the package was not affiliated with the project, and researchers linked the releases to a coordinated campaign using shared infrastructure. Organizations were urged to remove affected packages, review lockfiles and CI/CD logs, block the rogue package, and rotate any credentials that may have been exposed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
By 2026-05-12, researchers reported that the Mini Shai-Hulud supply-chain campaign had grown to 373 malicious package-version entries spanning 169 npm package names, including packages in namespaces such as @tanstack, @mistralai, @uipath, @tallyui, and others. The campaign was described as stealing developer and CI/CD credentials and using them to publish additional compromised packages, with malicious lifecycle execution tied to a GitHub-hosted optional dependency named @tanstack/setup.
By 2026-05-04, Endor Labs reported that the malicious SAP-published npm package versions were part of the Mini Shai-Hulud campaign. The firm said shared indicators including the Bun bootstrap, ctf-scramble-v2 cipher family, and a matching PBKDF2 key tied the SAP compromise to the earlier Shai-Hulud activity.
Following analysis by multiple security firms, the four SAP-related npm packages compromised in the April 29 supply-chain attack were later deprecated from the npm repository. This marked a broader remediation step beyond the earlier unpublishing of a single malicious package version.
By 2026-04-30, reporting said the supply-chain campaign affecting SAP-related npm packages had expanded to also compromise the intercom-client npm package and the lightning package on PyPI. Researchers linked the activity to TeamPCP and described malware that steals developer and CI/CD secrets, exfiltrates data via GitHub repositories, and attempts to propagate into additional repositories and package distributions.
On 2026-04-30, SAP issued Security Note 3747787 in response to the malicious npm package versions affecting its Cloud Application Programming ecosystem. The note marked an official vendor remediation and guidance step alongside replacement package releases.
By 2026-04-30, clean replacement versions had been published for @cap-js/sqlite, @cap-js/postgres, and @cap-js/db-service following the malicious 2026-04-29 releases. The reference noted that mbt@1.2.48 still remained the latest dist-tag without a remediated successor at the time of writing.
By 2026-04-29, Tanner Linsley confirmed the unscoped tanstack package was not affiliated with the official TanStack project and described it as part of an ongoing brandjacking issue tied to sh20raj. He also said TanStack had pursued legal action and repeatedly asked npm to intervene.
On 2026-04-29, Endor Labs reported that the SAP ecosystem npm compromise occurred through two separate paths: a stolen static npm token for mbt and a compromised GitHub account combined with overly broad npm OIDC trusted publishing for the @cap-js packages. The report also tied the attack tradecraft to the broader Mini Shai-Hulud activity.
On 2026-04-29, Socket disclosed a suspected software supply-chain attack affecting SAP CAP-related npm packages. The report highlighted risky behaviors including redirect-following without destination validation and PowerShell execution with -ExecutionPolicy Bypass on Windows.
On 2026-04-29, Socket reported that the malicious tanstack package was part of an active npm supply-chain attack and said its automated detection identified the postinstall exfiltration behavior. Socket also linked the malicious releases through a shared Svix source ID, indicating a coordinated campaign by a single actor.
By 2026-04-29, @cap-js/sqlite@2.2.2 appeared to have already been unpublished following the suspicious package activity. This indicates at least partial removal of one affected release from npm.
On 2026-04-29, several npm packages tied to SAP's JavaScript and cloud application development ecosystem, including mbt and multiple @cap-js packages, published suspicious versions within a short window. These releases added a new preinstall script that downloaded Bun from GitHub Releases, extracted it, and executed it during installation, creating an unexpected code execution path in developer and CI/CD environments.
On 2026-04-29, the npm maintainer account "sh20raj" published tanstack versions 2.0.4 through 2.0.7 within 27 minutes. The unscoped package impersonated the legitimate TanStack ecosystem and used postinstall scripts to exfiltrate local files, especially .env variants, to an attacker-controlled Svix endpoint.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcetheregister.com
Open sourceendorlabs.com
Open sourcesocket.dev
Open sourcethreats.wiz.io
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.