logo

Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware (Campaign)

ID: a990abc3-311e-5ef9-9875-a06cf1e198a3

STIX ID: report--a990abc3-311e-5ef9-9875-a06cf1e198a3

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2026-04-29

Date Updated: 2026-05-11

Author: [email protected] (Wiz Threat Research)

...
...

Malicious versions of SAP ecosystem npm packages (e.g., @cap-js/sqlite, @cap-js/postgres) included a preinstall script that runs setup.mjs to download the Bun runtime and execute an obfuscated payload. The second-stage payload is a credential stealer and propagation framework that targets developer environments and CI/CD pipelines, collects GitHub, npm, cloud and Kubernetes credentials (including extracting secrets from runner memory), exfiltrates encrypted payloads via public GitHub repositories, propagates to additional repositories/packages, and contains a locale-based kill-switch to avoid Russian-speaking systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.