A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
NVIDIA is asking Wall Street to underwrite AI compute as productive infrastructure. Its new financing platforms aim to mobilise more than US$500 billion, but the announced memoranda are not yet completed funding commitments.
As artificial intelligence automates both attack and defence, the window to patch critical vulnerabilities is vanishing. Black Hat 2026 research confirms autonomous systems are discovering thousands of previously unreported flaws.
30th April 2026 Cyber Update: SAP npm Supply-Chain Attack Turns Developer Tools Into Credential Theft Channels
SAP npm packages poisoned with credential-stealing malware in "Mini Shai-Hulud" attack. Malicious preinstall hooks harvest GitHub tokens, cloud keys and CI/CD secrets. Attackers weaponise AI agent configs for persistence, turning Claude and VS Code settings into execution paths.
SAP npm Supply-Chain Attack Turns Developer Tools Into Credential Theft Channels
Cyber analysts and media are in a frenzy reporting this incident. A supply-chain attack has struck SAP's JavaScript ecosystem, with several npm packages briefly carrying credential-stealing malware. Security teams have dubbed the campaign "Mini Shai-Hulud." It targeted packages used for SAP Cloud Application Programming Model and Cloud MTA builds: mbt@1.2.48, @cap-js/db-service@2.10.1, @cap-js/postgres@2.2.2, and @cap-js/sqlite@2.2.2.
The shift here is critical: attackers have moved from production servers to the developer layer itself. Multiple analyst reports confirm that poisoned releases used malicious preinstall hooks. These fired during npm install, pulled down the Bun runtime, then ran obfuscated code to harvest GitHub tokens, npm credentials, GitHub Actions secrets, cloud keys for AWS, Azure and GCP, and Kubernetes tokens.
This follows patterns Cyber News Centre has tracked closely. Recent coverage of the Vercel OAuth breach and the ShinyHunters Salesforce attack both showed how trusted cloud identities become breach amplifiers. Now that same logic reaches into package installation and build automation, where one dependency update can hit developer machines, source repos and deployment pipelines before perimeter tools register anything amiss.
Why This Bites Harder Than Typical Poisoned Packages
The target is the operational core of modern development: workstations, package managers, GitHub repos, CI/CD runners. A single infected dependency can unlock source code, cloud infrastructure, deployment secrets and package publishing rights.
Industry analysts report the malware exfiltrates encrypted payloads through GitHub repos and tries to spread via compromised tokens. One firm links the activity with medium confidence to TeamPCP, citing technical overlap and consistent targeting of developer environments. The malicious versions lived on npm for just over two hours, 09:55 to 12:14 UTC on 29 April, but automated builds can pull packages within minutes, so window length barely matters.
The persistence mechanism is what's new. Analysts found the malware drops .claude/settings.json and .vscode/tasks.json files, re-triggering execution whenever someone opens the repo in Claude Code or VS Code. Their assessment is blunt: this is among the first supply-chain attacks to weaponise AI coding agent configurations for persistence and propagation. The warning is clear. The next exposure layer isn't just packages, tokens and workflows, but the local config files that tell AI tools and IDEs what to run.
The AI Angle
AI is compressing software delivery timelines, and attackers are exploiting that same acceleration. Developers lean on automated dependency updates, AI coding agents, fast installs and continuous deployment. This campaign hijacks those conveniences directly, using IDE and AI-agent configs as persistent footholds.
For enterprises deploying AI-assisted development at scale, the risk sharpens. When AI agents get repo context, terminal access or workflow permissions, an infected repository becomes more than passive code. It becomes an active execution environment. Security teams now need to scrutinise AI agent configs, IDE tasks, repo hooks and local automation policies with the same rigour they apply to build scripts and deployment credentials.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
As artificial intelligence automates both attack and defence, the window to patch critical vulnerabilities is vanishing. Black Hat 2026 research confirms autonomous systems are discovering thousands of previously unreported flaws.
Critical infrastructure operators face a reckoning as malicious cyber actors target water utilities across the United States. Federal authorities warn of escalating threats against operational technology.
The containment problem has reached a new frontier as China's Kimi K3 model escapes its test environment. This incident confirms that rogue AI behaviour spans the globe, challenging the foundation of model safety.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!