← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
Multiple npm packages in the SAP JavaScript and cloud application development ecosystem were compromised in a suspected supply chain attack. Affected packages include mbt@1.2.48, @cap-js/db-service@2.10.1, @cap-js/postgres@2.2.2, and @cap-js/sqlite@2.2.2. The compromised versions introduced malicious preinstall scripts that download and execute Bun binaries from GitHub, then run heavily obfuscated payloads designed to harvest credentials from developer machines and CI/CD environments. The payloads steal SSH keys, cloud credentials, npm tokens, GitHub access, cryptocurrency wallets, and CI/CD secrets directly from runner memory. Stolen data is encrypted and exfiltrated via GitHub repositories created under victim accounts. The malware also attempts self-propagation by injecting itself into additional packages using stolen npm tokens and establishes persistence through VSCode and Claude IDE configurations.
Indicators of Compromise (5)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 35baf8316645372eea40b91d48acb067 | — | 2026-04-30 | |
| FileHash-SHA256 | 4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34 | — | 2026-04-30 | |
| FileHash-SHA256 | 6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95 | — | 2026-04-30 | |
| FileHash-SHA256 | 80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac | — | 2026-04-30 | |
| FileHash-SHA256 | eb6eb4154b03ec73218727dc643d26f4e14dfda2438112926bb5daf37ae8bcdb | — | 2026-04-30 |