216.73.216.6

Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages

· Published 30/04/2026 00:12 · Modified 30/04/2026 07:47

Export JSON

Essential information

Published
30/04/2026 00:12
Modified
30/04/2026 07:47
Tags
2026-04-30 bun-binary ci-cd-compromise credential-theft github abuse npm packages obfuscation sap-cap supply chain attack
Related entities
4 observables, 1 intrusion sets (apt), 1 others

Description

Multiple in the SAP JavaScript and cloud application development ecosystem were compromised in a suspected . Affected packages include [email protected], @cap-js/[email protected], @cap-js/[email protected], and @cap-js/[email protected]. The compromised versions introduced malicious preinstall scripts that download and execute Bun binaries from GitHub, then run heavily obfuscated payloads designed to harvest credentials from developer machines and CI/CD environments. The payloads steal SSH keys, cloud credentials, npm tokens, GitHub access, cryptocurrency wallets, and CI/CD secrets directly from runner memory. Stolen data is encrypted and exfiltrated via GitHub repositories created under victim accounts. The malware also attempts self-propagation by injecting itself into additional packages using stolen npm tokens and establishes persistence through VSCode and Claude IDE configurations.

External references