SAP-Related npm Packages Hit by Credential-Stealing Malware Attack
Cybersecurity experts have raised alarms over a supply chain attack targeting SAP-related npm packages. The campaign, dubbed “mini Shai-Hulud,” compromised several popular packages, including mbt@1.2.48 and @cap-js/db-service@2.10.1, which were found to contain malware designed to steal sensitive credentials.
The attack affects developers and organizations using these SAP packages, as the malware can harvest local credentials, GitHub tokens, and cloud secrets from platforms like AWS and Azure. Once stolen, this data is encrypted and exfiltrated to public GitHub repositories.
To protect against similar threats, developers are advised to update to the newly released safe versions of the affected packages, regularly audit their repositories, and implement strict permission controls.
Risk Level: High. Given the malware’s ability to self-propagate and compromise developer workflows, organizations should act swiftly to mitigate potential impacts.
Source: View Original Report
