SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack

A new supply chain assault operation using malware that steals credentials is targeting SAP-related npm packages, according to cybersecurity analysts.

The campaign, dubbed the “mini Shai-Hulud,” has impacted the following packages connected to SAP’s JavaScript and cloud application development environment, according to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz:

  • mbt@1.2.48
  • @cap-js/db-service@2.10.1
  • @cap-js/postgres@2.2.2
  • @cap-js/sqlite@2.2.2

According to Socket, the impacted versions added new installation-time behavior that wasn’t previously included in these packages’ anticipated capabilities. A preinstall script that functions as a runtime bootstrapper was added to the compromised releases. It downloads and extracts a platform-specific Bun ZIP file from GitHub Releases, then launches the extracted Bun binary right away read more about SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *