The never-ending supply chain attacks worm into SAP npm packages, other dev tools
ID: 785aa60d-21d4-536f-82e0-0a1e87698c57
STIX ID: report--785aa60d-21d4-536f-82e0-0a1e87698c57
Feed Name: The Register (Security)
Multiple widely used npm and PyPI packages (including SAP-related mbt and @cap-js packages, intercom-client, and Lightning) were compromised in a supply-chain campaign attributed to TeamPCP; the malicious releases deploy multi-stage credential-stealing malware that runs via preinstall/import hooks, extracts secrets (including runner memory and cloud/GitHub tokens), self-propagates to other repositories and packages, and exfiltrates encrypted data to public GitHub repositories, posing high risk to developer environments and CI/CD pipelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
