PULSE NAME
Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
WHITE TeamPCP AlienVault 2026-04-30 Modified: 2026-04-30
5
IOCs
LOW VOLUME
Multiple npm packages in the SAP JavaScript and cloud application development ecosystem were compromised in a suspected supply chain attack. Affected packages include mbt@1.2.48, @cap-js/db-service@2.10.1, @cap-js/postgres@2.2.2, and @cap-js/sqlite@2.2.2. The compromised versions introduced malicious preinstall scripts that download and execute Bun binaries from GitHub, then run heavily obfuscated payloads designed to harvest credentials from developer machines and CI/CD environments. The payloads steal SSH keys, cloud credentials, npm tokens, GitHub access, cryptocurrency wallets, and CI/CD secrets directly from runner memory. Stolen data is encrypted and exfiltrated via GitHub repositories created under victim accounts. The malware also attempts self-propagation by injecting itself into additional packages using stolen npm tokens and establishes persistence through VSCode and Claude IDE configurations.
Indicators of Compromise (5)
All FileHash-MD5 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 35baf8316645372eea40b91d48acb067 2026-04-30
FileHash-SHA256 4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34 2026-04-30
FileHash-SHA256 6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95 2026-04-30
FileHash-SHA256 80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac 2026-04-30
FileHash-SHA256 eb6eb4154b03ec73218727dc643d26f4e14dfda2438112926bb5daf37ae8bcdb 2026-04-30