# Mini Shai-Hulud (TeamPCP): SAP CAP and PyTorch Lightning Cross-Registry Compromise

- **Artifact ID:** CHQ-EX-2026-017
- **Public record:** https://record.cybersecurityhq.com/exhibits/chq-ex-2026-017
- **Machine-record SHA-256:** `8fa90823e040916c076f0fec2abea4aeb2ebdb302f21dfbbb15615c96d84494f`

## Complete structured record

```json
{
  "id": "CHQ-EX-2026-017",
  "title": "Mini Shai-Hulud (TeamPCP): SAP CAP and PyTorch Lightning Cross-Registry Compromise",
  "subtitle": "TeamPCP executed a coordinated supply chain compromise across npm and PyPI through OIDC trusted publishing abuse and developer account takeover, deployed a self-propagating credential stealer that weaponized AI coding agent runtime configuration as a persistence vector, and seeded over one thousand poisoned repositories during the operational window.",
  "classification_notice": [
    "This document is published as a CHQ Exhibit. It records historical conditions, breach events, and industry practices as they existed during the periods described. This Exhibit records observed conditions, exploitation mechanics, and structural patterns as documented in public disclosures, security research publications, and vendor advisories during the stated period.",
    "This document does not address present conditions and carries no current applicability. No evaluation of past practices is intended or implied.",
    "CHQ Exhibits are not superseded by later artifacts unless explicitly invalidated for factual error."
  ],
  "metadata": {
    "artifact_class": "EXHIBIT",
    "temporal_scope": "OPERATIONAL (APRIL 29–30, 2026)",
    "authority_level": "NON-JUDGMENTAL",
    "reliance_status": "EXHIBIT_ONLY",
    "update_policy": "ERRATA_ONLY",
    "temporal_start": "2026-04-29",
    "temporal_end": "2026-04-30"
  },
  "sections": [
    {
      "heading": "I. Factual Record",
      "content": [
        "Threat Actor: TeamPCP, the same actor cluster previously documented in the Trivy, Checkmarx KICS, Checkmarx AST, and LiteLLM PyPI compromises during March 2026. Wiz Research confirmed attribution based on shared RSA-4096 key material, encoding routines, and Russian-locale geofencing fingerprints consistent with prior TeamPCP operations. Naming “Mini Shai-Hulud” originated in attacker-side artifacts: malicious payloads created exfiltration repositories with the description string “Mini Shai-Hulud”.",
        "SAP CAP Compromise: Between 09:55 and 14:00 UTC on April 29, 2026, malicious versions of four SAP Cloud Application Programming model packages were published to npm: @cap-js/sqlite version 2.2.2, @cap-js/postgres, @cap-js/db-service, and mbt. Publication occurred via abuse of GitHub Actions OIDC trusted publishing. The attacker compromised an SAP developer account with release workflow permissions, modified the GitHub Actions release workflow to extract the short-lived OIDC token at publication time, and used the token within its valid window to publish backdoored versions to the official @cap-js npm scope. The packages were signed. They came from the official scope. They passed every automated check.",
        "PyTorch Lightning Compromise: On April 30, 2026, malicious versions of pytorch-lightning 2.6.2 and 2.6.3 were published to PyPI via the same campaign. The same Bun-based credential stealer was deployed.",
        "Payload Mechanism: The malicious packages used npm’s preinstall lifecycle hook (setup.mjs) to download the Bun JavaScript runtime to the host, then executed an eleven-megabyte obfuscated payload (execution.js) inside Bun. The use of Bun rather than Node.js evaded detection signatures and analysis tooling oriented toward Node-based supply chain attacks. The payload harvested GitHub and npm tokens, AWS, Azure, GCP, and Kubernetes secrets, CI/CD secrets, and browser-stored credentials.",
        "Self-Propagation: Stolen GitHub tokens were used to inject malicious GitHub Actions workflows into victim repositories the compromised developer had push access to. By the end of the operational window, more than 1,100 attacker-created repositories with the “Mini Shai-Hulud” descriptor had been observed.",
        "AI Coding Agent Persistence — First Documented Instance: The payload injected .claude/settings.json with a malicious SessionStart hook into poisoned repositories. Opening such a repository in Claude Code triggered execution of the malware on the developer’s machine. A parallel mechanism using .vscode/tasks.json with runOn: folderOpen provided equivalent functionality in VS Code. The malware also scanned for and injected itself into Claude Code, Gemini CLI, Codex CLI, and Cursor configuration.",
        "Cryptographic Profile: Payload encryption used AES-256-GCM with RSA-4096 key wrapping. Russian locale geofencing and shared encoding routines matched TeamPCP fingerprints from prior operations.",
        "Disclosure and Remediation: Aikido Security, Wiz Research, Sophos, StepSecurity, SafeDep, Socket, and Onapsis published independent technical analyses. SAP confirmed the unauthorized workflow modification and released clean package versions."
      ]
    },
    {
      "heading": "II. Failure Pattern",
      "content": [
        "The compromise demonstrates that GitHub Actions OIDC trusted publishing — an infrastructure layer adopted across npm, PyPI, and other registries as a security improvement over long-lived publishing tokens — is itself a target surface. The trust model assumes that the workflow generating the token is trustworthy. The attacker compromised the workflow.",
        "Compromise of a developer account with release workflow permissions is now sufficient to publish into trusted distribution channels through a path that produces packages indistinguishable from legitimate releases at the registry level. The package is signed. It comes from the official scope. It passes integrity verification. The compromise occurred upstream of the integrity boundary the registry verifies.",
        "The cross-registry expansion is the second structural element. The campaign targeted npm and PyPI in the same operational window using shared payload infrastructure. The actor is operating at the level of publishing trust models as a category, not at the level of individual ecosystems.",
        "The AI coding agent persistence mechanism is the third element and represents a novel attack surface class. AI coding agents trust repository configuration at session initialization without verifying its provenance. Opening a poisoned repository becomes an execution trigger independent of credential theft. The mechanism converts a repository into a persistent execution surface on every developer machine that opens it.",
        "The SAP CAP target selection is the fourth element. CAP is the de facto custom development framework for SAP’s enterprise customer base. The target selection indicates strategic expansion from consumer-developer ecosystems to enterprise business infrastructure with deeper credential exposure surfaces."
      ]
    },
    {
      "heading": "III. Referenced By",
      "content": [
        "CHQ-P-2026-013 — Position: Portable Developer Identity Cannot Contain Credential Compromise Across Registries.",
        "CHQ-P-2026-014 — Position: Management Plane Compromise Produces Deterministic Control That Operates Outside Identity Enforcement.",
        "CHQ-P-2026-015 — Position: Execution Pipelines Function as Control Planes Without Verification Primitives Capable of Validating the Authority They Execute.",
        "CHQ-SM-2026-012 — Memorandum: The Developer Supply Chain Is Now Self-Propagating.",
        "CHQ-SM-2026-014 — Memorandum: Publication Authority Inheritance as Structural Attack Surface.",
        "CHQ-ED-2026-016 — Evidence Docket: CHQ-P-2026-013 (Portable Developer Identity).",
        "CHQ-ED-2026-018 — Evidence Docket: CHQ-P-2026-015 (Execution Pipelines as Control Planes, successor docket)."
      ]
    }
  ],
  "closing_statement": "This Exhibit records historical conditions. It carries no present applicability. No judgment is made about any organization, vendor, security posture, or attribution conclusion.\n\nTemporal scope: April 29–30, 2026. Exhibit issuance date is May 4, 2026. This Exhibit records findings as reported by named security research organizations, not as established fact.\n\nSources: Aikido Security, Wiz Research, Sophos, StepSecurity, SafeDep, Socket, Onapsis, SAP official statement, GitHub Security Advisory.",
  "hash_scope": "Full exhibit content body",
  "hash_generated": "2026-05-04"
}
```
