logo

Malicious SAP npm Packages Target GitHub, Cloud, and AI Coding Tokens

ID: 25f32a43-27cc-539a-b5ef-1d10819baa9b

STIX ID: report--25f32a43-27cc-539a-b5ef-1d10819baa9b

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Varshini

...
...

**Executive Summary:** On April 29, 2026 a supply-chain campaign compromised four official SAP-related npm packages (mbt, @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service) to deliver an obfuscated 11.7 MB credential-stealing malware that exfiltrates npm/GitHub/cloud tokens, SSH keys, Kubernetes tokens, and AI assistant configs by creating public GitHub repositories as dead drops and by self-replicating into victims' projects; attackers abused a stolen long-lived npm automation token and a compromised GitHub account with misconfigured OIDC, and defenders are advised to remove poisoned packages, rotate all exposed secrets, and audit CI/CD and token usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.