Shai Hulud SAP Supply Chain Attack via AI Assistant
Score: 9/10

Shai Hulud SAP Supply Chain Attack via AI Assistant

The Shai Hulud threat actor compromised SAP CAP framework packages by exploiting an AI coding assistant's GitHub integration to inject malicious code and steal npm OIDC tokens.

Executive Summary

On April 29, 2026, a threat actor identified as the 'Shai Hulud' group (previously linked to a Bitwarden CLI compromise) successfully executed a supply chain attack against SAP's Cloud Application Programming (CAP) model. The attacker compromised four core SAP open-source libraries at the source: @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service, and mbt. SAP mitigated the threat within hours, but the incident highlights a novel attack vector using AI tools.

The technical significance of this attack lies in its use of an AI coding assistant (Claude Code) already running on an infected developer's machine. By leveraging the tool's legitimate GitHub write permissions, the attacker pushed malicious commits under the identity 'claude@users.noreply.github.com' to SAP's repositories. These commits modified CI/CD workflows to extract npm OIDC tokens and deploy highly obfuscated malware that targets cloud credentials, SSH keys, and AI tool configurations.

This campaign demonstrates an advanced shift in adversary tradecraft, transitioning from simple credential theft to exploiting the automated trust between AI development tools and corporate repositories. The malware specifically targets developers and DevOps engineers, aiming to gain persistent access to cloud infrastructure and private code repositories through repository-based persistence hooks.

Key Details

Threat Name

Shai Hulud SAP Supply Chain Attack

Affects

—

Adversary

—

Malware/Tools

Shai Hulud

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure10
Technical Depth10

Sources