Meta’s Muse is more than a chatbot. It is a digital worker that can read email, make purchases across the web, and act after users close the app. Wall Street sees a return on Meta’s vast AI spending. Cybersecurity experts see a more urgent question: should it hold the keys to our digital lives yet?
Dell’s US$95 billion AI-server backlog and US$74 billion revenue outlook show the AI boom moving beyond a few cloud giants into enterprise, sovereign and neocloud infrastructure procurement.
Meta has come back to the consumer, and it has come back armed. Muse reads inboxes, drives a browser, books travel and pays. Meta has not led with intelligence. It has led with containment. A model that says the wrong thing is an embarrassment. An agent that does the wrong thing is now an incident.
30th April 2026 Cyber Update: SAP npm Supply-Chain Attack Turns Developer Tools Into Credential Theft Channels
SAP npm packages poisoned with credential-stealing malware in "Mini Shai-Hulud" attack. Malicious preinstall hooks harvest GitHub tokens, cloud keys and CI/CD secrets. Attackers weaponise AI agent configs for persistence, turning Claude and VS Code settings into execution paths.
SAP npm Supply-Chain Attack Turns Developer Tools Into Credential Theft Channels
Cyber analysts and media are in a frenzy reporting this incident. A supply-chain attack has struck SAP's JavaScript ecosystem, with several npm packages briefly carrying credential-stealing malware. Security teams have dubbed the campaign "Mini Shai-Hulud." It targeted packages used for SAP Cloud Application Programming Model and Cloud MTA builds: mbt@1.2.48, @cap-js/db-service@2.10.1, @cap-js/postgres@2.2.2, and @cap-js/sqlite@2.2.2.
The shift here is critical: attackers have moved from production servers to the developer layer itself. Multiple analyst reports confirm that poisoned releases used malicious preinstall hooks. These fired during npm install, pulled down the Bun runtime, then ran obfuscated code to harvest GitHub tokens, npm credentials, GitHub Actions secrets, cloud keys for AWS, Azure and GCP, and Kubernetes tokens.
This follows patterns Cyber News Centre has tracked closely. Recent coverage of the Vercel OAuth breach and the ShinyHunters Salesforce attack both showed how trusted cloud identities become breach amplifiers. Now that same logic reaches into package installation and build automation, where one dependency update can hit developer machines, source repos and deployment pipelines before perimeter tools register anything amiss.
Why This Bites Harder Than Typical Poisoned Packages
The target is the operational core of modern development: workstations, package managers, GitHub repos, CI/CD runners. A single infected dependency can unlock source code, cloud infrastructure, deployment secrets and package publishing rights.
Industry analysts report the malware exfiltrates encrypted payloads through GitHub repos and tries to spread via compromised tokens. One firm links the activity with medium confidence to TeamPCP, citing technical overlap and consistent targeting of developer environments. The malicious versions lived on npm for just over two hours, 09:55 to 12:14 UTC on 29 April, but automated builds can pull packages within minutes, so window length barely matters.
The persistence mechanism is what's new. Analysts found the malware drops .claude/settings.json and .vscode/tasks.json files, re-triggering execution whenever someone opens the repo in Claude Code or VS Code. Their assessment is blunt: this is among the first supply-chain attacks to weaponise AI coding agent configurations for persistence and propagation. The warning is clear. The next exposure layer isn't just packages, tokens and workflows, but the local config files that tell AI tools and IDEs what to run.
The AI Angle
AI is compressing software delivery timelines, and attackers are exploiting that same acceleration. Developers lean on automated dependency updates, AI coding agents, fast installs and continuous deployment. This campaign hijacks those conveniences directly, using IDE and AI-agent configs as persistent footholds.
For enterprises deploying AI-assisted development at scale, the risk sharpens. When AI agents get repo context, terminal access or workflow permissions, an infected repository becomes more than passive code. It becomes an active execution environment. Security teams now need to scrutinise AI agent configs, IDE tasks, repo hooks and local automation policies with the same rigour they apply to build scripts and deployment credentials.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
OpenAI's Astra can develop zero-day exploits, while a US$1 billion defence push seeks to give critical infrastructure teams the same machine-speed advantage.
US authorities have dismantled QTFY’s QScan and QTRouter platforms, exposing a China-linked service model that blended exploit trading, automated scanning and hijacked IoT devices to reach critical infrastructure while concealing where attacks began.
Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!