logo

SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack

ID: 8a92eaf0-c2eb-5360-9cac-74a04c898773

STIX ID: report--8a92eaf0-c2eb-5360-9cac-74a04c898773

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers reported an active supply-chain campaign on April 29, 2026 that poisoned several SAP-related npm packages (e.g., @cap-js modules and mbt) by adding a preinstall script which downloads and runs a Bun-based credential-stealer and propagation framework. The payload harvests local developer credentials, GitHub/npm tokens, CI secrets, and cloud credentials (AWS/Azure/GCP/Kubernetes), encrypts exfiltrated data to victim-owned public GitHub repositories, and uses stolen tokens to inject malicious GitHub Actions and publish further poisoned packages; analysis attributes the campaign to the TeamPCP actor and notes novel persistence via AI coding-agent and VS Code configuration abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.