SAP npm Packages Hijacked in Suspected TeamPCP Supply-Chain Attack, Developer Secrets Stolen

Listen to this Post

Featured Image

Introduction

A serious software supply-chain security incident has shaken enterprise development environments after multiple official SAP npm packages were found compromised. Researchers believe the attack is linked to the threat group known as TeamPCP, a name already associated with several high-profile ecosystem intrusions.

The tampered packages were reportedly used to steal authentication tokens, cloud credentials, SSH keys, CI/CD secrets, and developer data from infected systems. Because these packages are tied to SAP development tools widely used in enterprise environments, the impact could extend far beyond individual developers.

This incident highlights a growing reality in cybersecurity: trusted software repositories are now prime targets, and one poisoned package can create access to thousands of organizations at once.

Compromised SAP Packages Identified

Security researchers stated that four official SAP npm packages were affected, and the malicious versions have since been deprecated from npm.

The impacted packages include:

@cap-js/sqlite – v2.2.2

@cap-js/postgres – v2.2.2

@cap-js/db-service – v2.10.1

mbt – v1.2.48

These packages are connected to SAP’s Cloud Application Programming Model (CAP) and Cloud MTA tooling, both commonly used by developers building enterprise cloud applications.

Because these tools are integrated into development pipelines, many installations may have happened automatically through CI/CD systems rather than manual user action.

How the Attack Worked

Researchers from Aikido and Socket explained that the malicious versions contained a hidden preinstall script.

This is dangerous because preinstall scripts run automatically during package installation. In many cases, users never notice them.

The script reportedly launched a file named setup.mjs, which then downloaded the Bun JavaScript runtime from GitHub. Bun was then used to execute another heavily obfuscated payload named execution.js.

That second-stage payload functioned as an advanced information stealer.

Once active, it searched systems for valuable secrets and transmitted the stolen data to attacker-controlled locations.

What Data Was Targeted

The malware was built to steal a wide range of sensitive credentials from both developer workstations and CI/CD runners.

Reported targets included:

npm authentication tokens

GitHub access tokens

SSH keys

AWS credentials

Microsoft Azure secrets

Google Cloud credentials

Kubernetes configs and secrets

CI/CD environment variables

Developer login credentials

This makes the campaign especially dangerous because developers often hold access to multiple systems, repositories, and production environments.

Compromising one engineer can sometimes lead to compromising an entire company.

Memory Scraping on CI/CD Systems

One of the most alarming parts of the report was the malware’s ability to extract secrets directly from CI runner memory.

Researchers said the payload used an embedded Python script to inspect Linux memory structures such as /proc//maps and /proc//mem.

This technique allows attackers to capture secrets in memory before platforms can hide them in logs.

That means even properly masked CI variables may still be exposed if malware gains runner-level execution.

This tactic reportedly mirrors behavior seen in earlier attacks tied to TeamPCP.

GitHub Used as Dead-Drop Infrastructure

The attackers also allegedly used GitHub in a creative way.

Stolen data was encrypted and uploaded into public repositories under the victim’s own account. Some repositories reportedly used the phrase:

“A Mini Shai-Hulud has Appeared”

Researchers connected this phrase to previous TeamPCP campaigns using similar wording.

The malware also searched GitHub commit messages for hidden tokens. Encoded strings inside commits could be decoded into usable GitHub credentials.

This dead-drop method helps attackers hide communications in legitimate public platforms.

Self-Spreading Capability

The malicious code reportedly attempted to spread itself further.

Using stolen npm or GitHub credentials, it would try to modify other packages and repositories it could access.

Then it inserted the same malicious payload into new targets.

This transforms a single compromise into a scalable supply-chain outbreak.

It also explains why token theft remains one of the most valuable objectives for threat actors.

Possible Initial Access

At the time of reporting, it was still unclear how SAP’s package publishing pipeline was compromised.

However, Security Engineer Adnan Khan suggested an npm token may have been exposed through a misconfigured CircleCI job.

If true, that would mean a CI/CD weakness indirectly enabled malicious package publishing.

This is a common modern attack path: compromise automation, then compromise trust.

What Undercode Say:

This incident is another warning that software supply-chain attacks are no longer rare events. They are becoming one of the most efficient methods for cybercriminals and advanced threat groups.

Instead of attacking a company directly, adversaries now compromise tools developers already trust. Once a poisoned package enters the workflow, defenders are already behind.

The SAP ecosystem being targeted is significant. SAP environments are deeply embedded in global enterprises, finance systems, manufacturing, logistics, and internal business processes. That makes any compromise especially sensitive.

The use of preinstall scripts also shows why package managers need stricter controls. Automatic execution during install remains a dangerous feature when abused.

Another major lesson is token security. Organizations still underestimate how powerful npm, GitHub, and CI credentials can be. These are not simple login secrets. They are infrastructure keys.

The memory scraping capability is particularly advanced. Many teams believe masked variables in CI logs equal safety. They do not. If malware executes on the runner, secrets in memory may still be recoverable.

The use of GitHub as attacker infrastructure is clever because it blends malicious traffic into legitimate developer behavior. Security tools often trust GitHub domains, making detection harder.

Self-propagating package malware creates exponential risk. One compromised maintainer or build system can quickly affect dozens or hundreds of downstream projects.

Defenders should respond by rotating all exposed credentials, auditing CI pipelines, restricting token permissions, enabling short-lived credentials, and monitoring package integrity.

Companies should also review every external dependency, especially privileged developer tools.

The future of security is not only endpoint defense. It is trust-chain defense.

Fact Checker Results

✅ Multiple SAP npm packages were reportedly published with malicious code.
✅ Researchers linked tactics and code similarities to TeamPCP with medium confidence.
✅ CI/CD secrets and developer credentials were primary targets in the reported campaign.

Prediction

⚠️ More attackers will shift toward npm, PyPI, and other package ecosystems in 2026.
⚠️ Enterprises will begin enforcing stronger signing and provenance checks for dependencies.
⚠️ CI/CD platforms will add better memory-isolation protections after incidents like this.

🕵️‍📝Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.facebook.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon