criticalSupply chain·

AGS-2026-0002

SAP-related npm packages compromised by Mini Shai-Hulud (April 29, 2026)

What happened

On April 29, 2026 between 09:55–12:14 UTC, a wave of malicious SAP-namespaced npm packages was published carrying credential-stealing preinstall scripts. This was the precursor campaign that evolved into the TanStack attack two weeks later.

Indicators

  • Suspicious version bumps on SAP packages during the 2-hour window.
  • preinstall script in package.json invoking an inline obfuscated payload.
  • Outbound POST to a TeamPCP collector domain.

Self-check

AgentGuard subscribers receive this advisory automatically and their local guard runs the inspection below.

References