WordPress Malware Alert: SAP npm Packages Hacked for Credentials

Date:

SAP-Related npm Packages Hit by Credential-Stealing Malware Attack

Cybersecurity experts have raised alarms over a supply chain attack targeting SAP-related npm packages. The campaign, dubbed “mini Shai-Hulud,” compromised several popular packages, including mbt@1.2.48 and @cap-js/db-service@2.10.1, which were found to contain malware designed to steal sensitive credentials.

The attack affects developers and organizations using these SAP packages, as the malware can harvest local credentials, GitHub tokens, and cloud secrets from platforms like AWS and Azure. Once stolen, this data is encrypted and exfiltrated to public GitHub repositories.

To protect against similar threats, developers are advised to update to the newly released safe versions of the affected packages, regularly audit their repositories, and implement strict permission controls.

Risk Level: High. Given the malware’s ability to self-propagate and compromise developer workflows, organizations should act swiftly to mitigate potential impacts.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...