PULSE NAME
Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
WHITE TeamPCP AlienVault 2026-04-30 Modified: 2026-04-30
5
IOCs
LOW VOLUME
Multiple npm packages in the SAP JavaScript and cloud application development ecosystem were compromised in a suspected supply chain attack. Affected packages include mbt@1.2.48, @cap-js/db-service@2.10.1, @cap-js/postgres@2.2.2, and @cap-js/sqlite@2.2.2. The compromised versions introduced malicious preinstall scripts that download and execute Bun binaries from GitHub, then run heavily obfuscated payloads designed to harvest credentials from developer machines and CI/CD environments. The payloads steal SSH keys, cloud credentials, npm tokens, GitHub access, cryptocurrency wallets, and CI/CD secrets directly from runner memory. Stolen data is encrypted and exfiltrated via GitHub repositories created under victim accounts. The malware also attempts self-propagation by injecting itself into additional packages using stolen npm tokens and establishes persistence through VSCode and Claude IDE configurations.
Indicators of Compromise (1 / 5 total)
All FileHash-MD5 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 35baf8316645372eea40b91d48acb067 2026-04-30