Malicious SAP npm Packages Target GitHub, Cloud, and AI Coding Tokens
ID: 25f32a43-27cc-539a-b5ef-1d10819baa9b
STIX ID: report--25f32a43-27cc-539a-b5ef-1d10819baa9b
Feed Name: Cyber Press
**Executive Summary:** On April 29, 2026 a supply-chain campaign compromised four official SAP-related npm packages (mbt, @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service) to deliver an obfuscated 11.7 MB credential-stealing malware that exfiltrates npm/GitHub/cloud tokens, SSH keys, Kubernetes tokens, and AI assistant configs by creating public GitHub repositories as dead drops and by self-replicating into victims' projects; attackers abused a stolen long-lived npm automation token and a compromised GitHub account with misconfigured OIDC, and defenders are advised to remove poisoned packages, rotate all exposed secrets, and audit CI/CD and token usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
