SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack
A new supply chain assault operation using malware that steals credentials is targeting SAP-related npm packages, according to cybersecurity analysts.
The campaign, dubbed the "mini Shai-Hulud," has impacted the following packages connected to SAP's JavaScript and cloud application development environment, according to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz:
mbt@1.2.48
@cap-js/db-service@2.10.1
@cap-js/postgres@2.2.2
@cap-js/sqlite@2.2.2
According to Socket, the impacted versions added new installation-time behavior that wasn't previously included in these packages' anticipated capabilities. A preinstall script that functions as a runtime bootstrapper was added to the compromised releases. It downloads and extracts a platform-...


