30th April 2026 Cyber Update: SAP npm Supply-Chain Attack Turns Developer Tools Into Credential Theft Channels
SAP npm packages poisoned with credential-stealing malware in "Mini Shai-Hulud" attack. Malicious preinstall hooks harvest GitHub tokens, cloud keys and CI/CD secrets. Attackers weaponise AI agent configs for persistence, turning Claude and VS Code settings into execution paths.