SAP npm Packages Compromised to Harvest Developer and CI/CD Secrets
ID: df6a2a74-0436-591d-8692-1fcafbc3700f
STIX ID: report--df6a2a74-0436-591d-8692-1fcafbc3700f
Feed Name: cybersecurityNews.com
A supply-chain campaign dubbed 'mini Shai Hulud' compromised four SAP Cloud Application Programming Model (CAP) npm packages by injecting a preinstall hook that downloads the Bun runtime and runs an obfuscated 11 MB second-stage payload which steals GitHub, npm, cloud (AWS/Azure/GCP), Kubernetes, and CI/CD secrets and self-propagates by republishing infected packages; researchers attribute the campaign to TeamPCP and publish affected package versions, tarball and dropper hashes alongside mitigation guidance (rotate secrets, audit CI/CD, block listed versions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
