Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Tenet Security Emerges From Stealth With $6 Million Seed Funding

    June 18, 2026

    Precise Gene Editing in Early Human Embryos Reignites the ‘Designer Baby’ Debate

    June 18, 2026

    Lenovo ThinkStation P3 Tiny Gen 2 mini PC workstation review

    June 18, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom
    1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom
    Cybersecurity

    1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom

    The Tech GuyBy The Tech GuyMay 3, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Over 1,800 developers were affected by the Mini Shai-Hulud supply chain attack that hit the PyPi, NPM, and PHP ecosystems over the past two days.

    Advertisement

    Attributed to the TeamPCP hacking group, the campaign was first spotted on April 29, after malicious versions of four SAP NPM packages were caught delivering information-stealing malware and attempting to propagate to other packages.

    The malware would collect credentials, keys, tokens, and other secrets from the infected machines and publish the data to GitHub repositories containing the hardcoded description “A Mini Shai-Hulud has Appeared”.

    The same description has been used in a fresh round of infections linked to the compromise of the Lightning PyPi package and the intercom-client NPM package, which have a combined monthly download count of nearly 10 million.

    According to Ox Security, over 1,800 repositories containing stolen developer credentials have been created as part of the Mini Shai-Hulud attacks. The campaign appears to be a continuation of the Shai-Hulud supply chain attacks from late 2025.

    As part of the supply chain attack, the Lightning Python package versions 2.6.2 and 2.6.3 and the intercom-client NPM package versions 7.0.4 and 7.0.5 were injected with the information stealer.

    Advertisement. Scroll to continue reading.

    Additionally, the supply chain attack expanded to Packagist, through intercom-php version 5.0.2. A popular PHP package, intercom-php had over 20 million lifetime downloads.

    The Intercom compromise was a direct result of the Lightning supply chain attack. A local package installation used the infected Lightning PyPi package as a dependency, Socket reports.

    In addition to the malicious functions observed in the SAP compromise, the Lightning and Intercom payload added a dedicated infrastructure for data exfiltration, the zero[.]masscan[.]cloud domain, cybersecurity firm Wiz notes.

    The code also implements a dynamic fallback mechanism that searches GitHub for commits containing the ‘beautifulcastle’ and ‘EveryBoiWeBuildIsAWormyBoi’ strings to retrieve embedded command-and-control (C&C) commands, NetSkope says.

    Additionally, Wiz has observed the intercom-client payload actively scanning for Kubernetes environments and HashiCorp Vault secrets.

    “It queries Kubernetes service endpoints and Vault configurations, using extensive regex-based matching to extract credentials such as AWS keys, GitHub and npm tokens, database connection strings, private keys, and API secrets (e.g., Stripe, Slack, Twilio),” Wiz says.

    According to Aikido, the information stealer also targets VPN credentials, cryptocurrency wallet data, and Discord and Slack session data.

    Related: AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours

    Related: Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks

    Related: Checkmarx Confirms Data Stolen in Supply Chain Attack

    Related: Critical GitHub Vulnerability Exposed Millions of Repositories

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Tenet Security Emerges From Stealth With $6 Million Seed Funding

    June 18, 2026

    1Password Acquires Apono in Reported $250M-$300M Deal

    June 17, 2026

    Webinar Today: How Modern Breaches Bypass MFA and Evade Detection

    June 17, 2026

    Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

    June 17, 2026

    Magnitude Emerges From Stealth Mode With $10 Million in Funding

    June 17, 2026

    Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker

    June 16, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202672 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202618 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Tenet Security Emerges From Stealth With $6 Million Seed Funding

    June 18, 2026

    Precise Gene Editing in Early Human Embryos Reignites the ‘Designer Baby’ Debate

    June 18, 2026

    Lenovo ThinkStation P3 Tiny Gen 2 mini PC workstation review

    June 18, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.