:

SUPPLY CHAIN ATTACKS HIT SAP, INTERCOM, LIGHTNING

AI DESK2 MIN READ
FRI, MAY 1, 2026

■ AI-SUMMARIZED FROM 1 SOURCE BELOW

Security researchers have identified a coordinated supply chain campaign targeting popular development packages, compromising npm modules used by SAP and Intercom, as well as the PyPI package Lightning. The attack group calls itself Mini Shai-Hulud.

The latest wave of supply chain attacks has expanded its footprint, affecting widely-used packages across multiple ecosystems. Researchers discovered that threat actors successfully compromised packages relied upon by major enterprise software providers and communication platforms. The compromised npm packages include tools used by SAP and Intercom, two significant players in enterprise software and customer communication platforms respectively. Additionally, the Lightning package on PyPI, Python's official package repository, was also targeted in the same campaign. Supply chain attacks have become an increasingly common vector for threat actors seeking to distribute malware at scale. By compromising legitimate packages that developers download and integrate into their applications, attackers can potentially reach thousands of organizations with a single compromised release. The attackers behind this campaign have identified themselves as Mini Shai-Hulud, though the significance of the name remains unclear. The group's targeting of both JavaScript and Python ecosystems suggests a broad approach to penetrating development infrastructure. These attacks underscore the vulnerability of open-source software supply chains, where packages are often maintained by small teams with limited security resources. Organizations relying on affected packages are advised to review their dependencies and update to patched versions when available. Security experts continue to stress the importance of package verification, dependency scanning, and monitoring for unusual package behavior. The frequency of these supply chain compromises highlights the need for stronger security practices across software development environments and repository platforms.

■ SOURCES

Techmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The FBI is alerting carriers and freight brokers to a sharp rise in account hacking and cargo theft schemes. North American cargo theft losses jumped 60% year-over-year in 2025, with digital attacks now replacing traditional theft methods.

JUST NOWAI Desk

French authorities have detained a 15-year-old suspected of selling data stolen in a cyberattack on ANTS, France's agency for issuing and managing administrative documents.

JUST NOWAI Desk

Automatic license plate reader cameras operated by Flock Safety are generating false warrant alerts for a man who has never had one issued against him, creating a persistent police database error.

JUST NOWIndustry Desk

Minnesota has passed legislation prohibiting the creation and distribution of fake AI-generated nude images without consent. App developers face penalties up to $500,000 for violations.

JUST NOWAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.