SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack
ID: 8a92eaf0-c2eb-5360-9cac-74a04c898773
STIX ID: report--8a92eaf0-c2eb-5360-9cac-74a04c898773
Feed Name: The Hacker News
Cybersecurity researchers reported an active supply-chain campaign on April 29, 2026 that poisoned several SAP-related npm packages (e.g., @cap-js modules and mbt) by adding a preinstall script which downloads and runs a Bun-based credential-stealer and propagation framework. The payload harvests local developer credentials, GitHub/npm tokens, CI secrets, and cloud credentials (AWS/Azure/GCP/Kubernetes), encrypts exfiltrated data to victim-owned public GitHub repositories, and uses stolen tokens to inject malicious GitHub Actions and publish further poisoned packages; analysis attributes the campaign to the TeamPCP actor and notes novel persistence via AI coding-agent and VS Code configuration abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
