logo

SAP npm Packages Compromised to Steal Developers, CI/CD Secrets

ID: db9769f8-eccb-5b3a-a6f1-0077d3bab022

STIX ID: report--db9769f8-eccb-5b3a-a6f1-0077d3bab022

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Lucas Martin

...
...

**Executive summary:** A sophisticated supply‑chain campaign attributed to TeamPCP has been found injecting malicious preinstall hooks into SAP npm packages (notably @cap-js/sqlite v2.2.2, @cap-js/postgres v2.2.2, @cap-js/db-service v2.10.1, and mbt v1.2.48) to execute a multi‑stage credential‑stealing payload that harvests GitHub, npm, cloud, Kubernetes, CI/CD, and browser credentials and exfiltrates encrypted data to GitHub repositories via the GraphQL API; the operation includes a Russian‑locale kill‑switch, repository‑poisoning fallback, and multiple attribution overlaps with prior TeamPCP activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.