"A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages

2026-04-30T08:52:21Z1c2591990d62bac865aa0478f01969d767b7124a6839943ee2c9b51b2df52cbd
CVE-2026-40478advisoryagentic-architectureatlassianbackdoorcap-jscredential-stealergithub-actionsjirambtnpmpyPIsapsecurity-fixsnyk-advisorysupply-chainthymeleaf

What happened

Snyk blog posts (Apr 27–29, 2026) describe multiple high‑impact supply‑chain and template‑injection issues plus product news: a bun‑based stealer dubbed “Mini Shai‑Hulud” compromised SAP‑ecosystem npm packages (including cap‑js and mbt) via malicious releases; Thymeleaf template injection CVE‑2026‑40478 (CVSS 9.1) requires immediate patch to 3.1.4+ and auditing of dynamic view/template expressions; a malicious release of the elementary‑data PyPI CLI (v0.23.3) delivered a credential‑stealing backdoor (exfiltrating dbt profiles, cloud provider keys and SSH secrets) published via a GitHub Actions

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
snyk_blog
Record identifier
1c2591990d62bac865aa0478f01969d767b7124a6839943ee2c9b51b2df52cbd
Enrichment time
2026-04-30T08:52:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages · Baitaphish