A new supply chain assault operation using malware that steals credentials is targeting SAP-related npm packages, according to cybersecurity analysts.
The campaign, dubbed the “mini Shai-Hulud,” has impacted the following packages connected to SAP’s JavaScript and cloud application development environment, according to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz:
- mbt@1.2.48
- @cap-js/db-service@2.10.1
- @cap-js/postgres@2.2.2
- @cap-js/sqlite@2.2.2
According to Socket, the impacted versions added new installation-time behavior that wasn’t previously included in these packages’ anticipated capabilities. A preinstall script that functions as a runtime bootstrapper was added to the compromised releases. It downloads and extracts a platform-specific Bun ZIP file from GitHub Releases, then launches the extracted Bun binary right away read more about SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
