Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware (Campaign)
ID: a990abc3-311e-5ef9-9875-a06cf1e198a3
STIX ID: report--a990abc3-311e-5ef9-9875-a06cf1e198a3
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-04-29
Date Updated: 2026-05-11
Author: [email protected] (Wiz Threat Research)
Malicious versions of SAP ecosystem npm packages (e.g., @cap-js/sqlite, @cap-js/postgres) included a preinstall script that runs setup.mjs to download the Bun runtime and execute an obfuscated payload. The second-stage payload is a credential stealer and propagation framework that targets developer environments and CI/CD pipelines, collects GitHub, npm, cloud and Kubernetes credentials (including extracting secrets from runner memory), exfiltrates encrypted payloads via public GitHub repositories, propagates to additional repositories/packages, and contains a locale-based kill-switch to avoid Russian-speaking systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
