Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Credential-Stealing Attack Hits SAP npm Packages

Credential-Stealing Attack Hits SAP npm Packages

Posted on April 29, 2026 By CWS

Cybersecurity experts have raised alarms regarding a new supply chain attack affecting SAP-associated npm packages. The attack, identified by several security firms including Aikido Security and Google-owned Wiz, involves malware designed to steal credentials from affected systems.

The malicious operation, dubbed ‘mini Shai-Hulud,’ compromises specific packages within SAP’s JavaScript and cloud application development suite. These include versions of ‘[email protected],’ ‘@cap-js/[email protected],’ ‘@cap-js/[email protected],’ and ‘@cap-js/[email protected].’

Malicious Code and Execution

According to security reports, the compromised packages introduce unexpected installation behaviors. A preinstall script downloads and executes a platform-specific Bun ZIP file from GitHub, which is then used to initiate the malware. The implementation also follows HTTP redirects without proper validation, posing significant risks to developers and their environments.

Indicators suggest that these packages share features with known TeamPCP operations, hinting at the involvement of the same threat actor. The attack leverages a ‘setup.mjs’ file to run the Bun JavaScript runtime, which facilitates the execution of credential stealing scripts.

Data Harvesting and Propagation

The malware targets various credentials, including local developer information, GitHub tokens, and cloud secrets from major providers like AWS and Azure. Extracted data is encrypted and uploaded to GitHub repositories under the victim’s account, with over 1,100 repositories documented to date.

Notably, the attack’s payload can self-propagate, utilizing GitHub and npm tokens to insert malicious workflows into repositories. This allows attackers to access repository secrets and publish tampered npm packages.

Response and Mitigation

Investigations revealed that attackers compromised specific accounts to publish the malicious packages, exploiting configuration gaps in npm’s OIDC trusted publisher setup. As a defensive measure, package maintainers have issued secure updates to replace the affected versions.

StepSecurity highlighted that this attack is among the first to exploit AI coding agent configurations as a vector for persistence and spread. The compromised payload embeds itself into repositories, triggering execution when opened in development environments like Microsoft Visual Studio Code.

In summary, this incident underscores the need for robust security measures in software supply chains and highlights the evolving tactics of cyber adversaries. Organizations are urged to update affected packages and review security configurations to prevent similar breaches.

The Hacker News Tags:cloud development, credential theft, Cybersecurity, GitHub, JavaScript, Malware, NPM, SAP, Software Security, supply chain attack

Post navigation

Previous Post: Vimeo Data Breach Exposes User Database Details
Next Post: CISA Alerts on Critical Windows Shell Vulnerability

Related Posts

OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities The Hacker News
Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection The Hacker News
Masjesu Botnet: Global Threat to IoT Devices Masjesu Botnet: Global Threat to IoT Devices The Hacker News
Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and Harrods Four Arrested in £440M Cyber Attack on Marks & Spencer, Co-op, and Harrods The Hacker News
Malicious Rust Crates and AI Bot Threaten Developer Secrets Malicious Rust Crates and AI Bot Threaten Developer Secrets The Hacker News
Secure AI at Scale and Speed — Learn the Framework in this Free Webinar Secure AI at Scale and Speed — Learn the Framework in this Free Webinar The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Alerts on Critical Windows Shell Vulnerability
  • Credential-Stealing Attack Hits SAP npm Packages
  • Vimeo Data Breach Exposes User Database Details
  • DPRK Cyber Attacks Exploit AI and npm Malware
  • SLOTAGENT Malware Evades Detection with Advanced Techniques

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Alerts on Critical Windows Shell Vulnerability
  • Credential-Stealing Attack Hits SAP npm Packages
  • Vimeo Data Breach Exposes User Database Details
  • DPRK Cyber Attacks Exploit AI and npm Malware
  • SLOTAGENT Malware Evades Detection with Advanced Techniques

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark