Official SAP npm Packages compromised to steal Credentials and Authentication Tokens from Developers Systems.

Security researchers report that the compromise impacted four packages, with the versions now deprecated on NPM:

• @cap-js/sqlite – v2.2.2
• @cap-js/postgres – v2.2.2
• @cap-js/db-service – v2.10.1
• mbt – v1.2.48

⁉️These packages support SAP's Cloud Application Programming Model [CAP] and Cloud MTA, which are commonly used in enterprise development.⁉️

https://socket.dev/blog/sap-cap-npm-packages-supply-chain-attack

#sap #npmpackages #secure #programming #developer #security #privacy #infosec #tech #news

#Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository. https://www.theregister.com/2026/04/30/supply_chain_attacks_sap_npm_packages/?eicker.news #tech #media #news
The never-ending supply chain attacks worm into SAP npm packages, other dev tools

: Mini Shai-Hulud caught spreading credential-stealing malware

The Register

Malware Targets SAP npm Packages in Supply Chain Attack

A new supply-chain attack campaign, dubbed mini Shai-Hulud, is targeting SAP-related npm packages, delivering credential-stealing malware that threatens JavaScript and cloud applications. This sneaky attack puts sensitive data at risk, and experts are warning of a potentially massive impact.

https://osintsights.com/malware-targets-sap-npm-packages-in-supply-chain-attack?utm_source=mastodon&utm_medium=social

#SupplyChainAttack #MalwareOperations #Sap #NpmPackages #CredentialstealingMalware

Malware Targets SAP npm Packages in Supply Chain Attack

Learn how the mini Shai-Hulud supply-chain campaign targets SAP npm packages with credential-stealing malware and take steps to protect your organization now.

OSINTSights

How-To Geek: NPM packages are infected with malware, again. “It should be noted that the issue actually seems to spill over into the Maven ecosystem. Researchers observed that the malicious payload was present in org.mvnpm:posthog-node, a Maven artifact automatically generated from npm packages. This confirms that the automated bridging of software ecosystems can inadvertently bridge security […]

https://rbfirehose.com/2025/11/26/how-to-geek-npm-packages-are-infected-with-malware-again/

How-To Geek: NPM packages are infected with malware, again | ResearchBuzz: Firehose

ResearchBuzz: Firehose | Individual posts from ResearchBuzz
🐛 Oh joy, another thrilling episode of "Whack-a-Mole: Software Edition," where 300+ NPM packages show us that open source security is an oxymoron! 🎉 #HelixGuard struts in with their clipboard and magnifying glass, ready to save the day—right after the damage is done. 🔍📝
https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24 #openSourceSecurity #NPMpackages #softwareVulnerabilities #cybersecurity #HackerNews #ngated
HelixGuard

Supply chain security, vulnerability intelligence, and malware detection.

Moving Beyond the NPM elliptic Package

If you're in a hurry, head on over to soatok/elliptic-to-noble and follow the instructions in the README in order to remove the elliptic package from your project and all dependencies in node_modules. Art: CMYKat Why replace the elliptic package? Yesterday, the Trail of Bits blog published a post about finding cryptographic bugs in the elliptic library (a Javascript package on NPM) by using the Wycheproof.

http://soatok.blog/2025/11/19/moving-beyond-the-npm-elliptic-package/

#npm #crypto #cryptography #elliptic #security #infosec #cve #mitigation #appsec #javascript #js #npm #npmsecurity #npmpackages

Moving Beyond the NPM elliptic Package - Dhole Moments

If you’re in a hurry, head on over to soatok/elliptic-to-noble and follow the instructions in the README in order to remove the elliptic package from your project and all dependencies in node…

Dhole Moments

There's a new release for bgg-client, my JavaScript library for making it easier to use the BoardGameGeek API in your apps!

I've added validation, and have done a lot of work behind the scenes to ensure data integrity, more consistent typing, and better type-safety.

https://www.npmjs.com/package/bgg-client

#webdev #javascript #typescript #NPMPackages #boardgames

bgg-client

![NPM Version](https://img.shields.io/npm/v/bgg-client) ![NPM Downloads](https://img.shields.io/npm/dm/bgg-client) ![npm bundle size](https://img.shields.io/bundlephobia/min/bgg-client) ![GitHub License](https://img.shields.io/github/license/ghall89/bgg-c. Latest version: 2.0.0, last published: 5 minutes ago. Start using bgg-client in your project by running `npm i bgg-client`. There are no other projects in the npm registry using bgg-client.

npm

Just dropped a new release of bgg-client with a breaking change:

An API key from BoardGameGeek is now required.

https://www.npmjs.com/package/bgg-client

#webdev #javascript #NPMPackages #boardgames

bgg-client

![NPM Version](https://img.shields.io/npm/v/bgg-client) ![NPM Downloads](https://img.shields.io/npm/dm/bgg-client) ![npm bundle size](https://img.shields.io/bundlephobia/min/bgg-client) ![GitHub License](https://img.shields.io/github/license/ghall89/bgg-c. Latest version: 2.0.0, last published: 5 minutes ago. Start using bgg-client in your project by running `npm i bgg-client`. There are no other projects in the npm registry using bgg-client.

npm
🎩✨ "Let the little guys in," they say, as if trusting your bank account and ChatGPT with any random npm package is the next big thing! 🤡 Here’s a revolutionary thought: instead of locking down data, let’s just open the floodgates and watch as the personalized web devolves into majestic chaos. 🚀🌐
https://arjun.md/little-guys #OpenData #WebChaos #npmPackages #TrustInTech #PersonalizedWeb #HackerNews #ngated
Let the little guys in: Towards a context sharing runtime for the personalised web | Arjun Khoosal

Arjun's website :)

A colleague pointed me to this:
https://www.reversinglabs.com/blog/ethereum-contracts-malicious-code

TLDR: Some #malware in fake #npmpackages downloaded and executes commands stored in an #Ethereum #smartcontract , effectively abusing the contract as a command-and-control server.

#npm #smartcontracts

Ethereum smart contracts used to push malicious code on npm | ReversingLabs

RL discovered how the contracts were abused — and how this incident is part of a larger campaign to promote malicious packages on top repositories.

ReversingLabs