Executive Summary
On April 29, 2026, a threat actor identified as the 'Shai Hulud' group (previously linked to a Bitwarden CLI compromise) successfully executed a supply chain attack against SAP's Cloud Application Programming (CAP) model. The attacker compromised four core SAP open-source libraries at the source: @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service, and mbt. SAP mitigated the threat within hours, but the incident highlights a novel attack vector using AI tools.
The technical significance of this attack lies in its use of an AI coding assistant (Claude Code) already running on an infected developer's machine. By leveraging the tool's legitimate GitHub write permissions, the attacker pushed malicious commits under the identity 'claude@users.noreply.github.com' to SAP's repositories. These commits modified CI/CD workflows to extract npm OIDC tokens and deploy highly obfuscated malware that targets cloud credentials, SSH keys, and AI tool configurations.
This campaign demonstrates an advanced shift in adversary tradecraft, transitioning from simple credential theft to exploiting the automated trust between AI development tools and corporate repositories. The malware specifically targets developers and DevOps engineers, aiming to gain persistent access to cloud infrastructure and private code repositories through repository-based persistence hooks.
