SAP
Disclosed Apr 29, 20264 months agoUnverified
Official SAP npm packages trojanized to steal developer credentials
Malicious versions of official SAP npm packages, including @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service and mbt, ran a preinstall script that stole npm, GitHub, cloud and Kubernetes secrets from developers. Researchers linked the attack to TeamPCP; SAP did not comment.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Apr 29, 2026 |
| Attack | Supply chain |
| Data exposed | Credentials and tokens, API keys |
| Sector | Tech · DE |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Official SAP npm packages compromised to steal credentialsbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Apr 29 |
Other breaches at SAP
| Breach | Affected | ||||
|---|---|---|---|---|---|
| SAPwned: SAP AI Core flaws gave researchers access to customer cloud keys and AI artifactsJul 17, 20242 years agoExposed dataUnverified | Jul 17, 20242 years ago | Exposed data | Tech | Unverified | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.