:

SUPPLY CHAIN ATTACKS HIT SAP, INTERCOM, LIGHTNING

AI DESK2 MIN READ
FRI, MAY 1, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Security researchers have identified a coordinated supply chain campaign targeting popular development packages, compromising npm modules used by SAP and Intercom, as well as the PyPI package Lightning. The attack group calls itself Mini Shai-Hulud.

The latest wave of supply chain attacks has expanded its footprint, affecting widely-used packages across multiple ecosystems. Researchers discovered that threat actors successfully compromised packages relied upon by major enterprise software providers and communication platforms. The compromised npm packages include tools used by SAP and Intercom, two significant players in enterprise software and customer communication platforms respectively. Additionally, the Lightning package on PyPI, Python's official package repository, was also targeted in the same campaign. Supply chain attacks have become an increasingly common vector for threat actors seeking to distribute malware at scale. By compromising legitimate packages that developers download and integrate into their applications, attackers can potentially reach thousands of organizations with a single compromised release. The attackers behind this campaign have identified themselves as Mini Shai-Hulud, though the significance of the name remains unclear. The group's targeting of both JavaScript and Python ecosystems suggests a broad approach to penetrating development infrastructure. These attacks underscore the vulnerability of open-source software supply chains, where packages are often maintained by small teams with limited security resources. Organizations relying on affected packages are advised to review their dependencies and update to patched versions when available. Security experts continue to stress the importance of package verification, dependency scanning, and monitoring for unusual package behavior. The frequency of these supply chain compromises highlights the need for stronger security practices across software development environments and repository platforms.

■ SOURCES

Techmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Fraudsters are exploiting Microsoft Teams and similar enterprise chat apps to deceive Chinese users into sending large sums of money. The trend has sparked a wave of complaints across the region.

2H AGOIndustry Desk

The Bureau of Alcohol, Tobacco, Firearms and Explosives has notified Congress of a major cybersecurity incident after a ransomware gang claimed responsibility for breaching the agency's systems.

2H AGOAI Desk

Google is rolling out Encrypted Client Hello (ECH) support in Android 17 to prevent network monitoring of user browsing activity. The privacy feature strengthens connection security across cellular and home networks.

7H AGOIndustry Desk

A new survey shows more Americans oppose police use of license plate readers than support them. The finding reflects growing concerns about surveillance overreach.

7H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.