"A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages
2026-04-30T08:52:21Z•1c2591990d62bac865aa0478f01969d767b7124a6839943ee2c9b51b2df52cbd
CVE-2026-40478advisoryagentic-architectureatlassianbackdoorcap-jscredential-stealergithub-actionsjirambtnpmpyPIsapsecurity-fixsnyk-advisorysupply-chainthymeleaf
What happened
Snyk blog posts (Apr 27–29, 2026) describe multiple high‑impact supply‑chain and template‑injection issues plus product news: a bun‑based stealer dubbed “Mini Shai‑Hulud” compromised SAP‑ecosystem npm packages (including cap‑js and mbt) via malicious releases; Thymeleaf template injection CVE‑2026‑40478 (CVSS 9.1) requires immediate patch to 3.1.4+ and auditing of dynamic view/template expressions; a malicious release of the elementary‑data PyPI CLI (v0.23.3) delivered a credential‑stealing backdoor (exfiltrating dbt profiles, cloud provider keys and SSH secrets) published via a GitHub Actions
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- snyk_blog
- Record identifier
- 1c2591990d62bac865aa0478f01969d767b7124a6839943ee2c9b51b2df52cbd
- Enrichment time
- 2026-04-30T08:52:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.