Skip to content

SAP

Disclosed Apr 29, 20264 months agoUnverified

Official SAP npm packages trojanized to steal developer credentials

Malicious versions of official SAP npm packages, including @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service and mbt, ran a preinstall script that stole npm, GitHub, cloud and Kubernetes secrets from developers. Researchers linked the attack to TeamPCP; SAP did not comment.

What is known

People affectedNot stated in the sources we have
DisclosedApr 29, 2026
AttackSupply chain
Data exposedCredentials and tokens, API keys
SectorTech · DE
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Source
Official SAP npm packages compromised to steal credentialsbleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalApr 29

Other breaches at SAP

BreachAffected
SAPwned: SAP AI Core flaws gave researchers access to customer cloud keys and AI artifactsJul 17, 20242 years agoExposed dataUnverifiedUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about SAP

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.