← Blog

SAP: Official CAP npm Packages Trojanized in Supply Wave

Share on X

April 29, 2026 security journalism and vendor analyses detailed a registry compromise affecting official SAP CAP-related npm packages, with preinstall malware chaining Bun loaders and obfuscated stealers targeting npm and GitHub credentials, SSH material, and cloud / CI secrets—pattern-matched by researchers to the broader TeamPCP Shai-Hulud-style supply-chain cluster affecting other vendors earlier in 2026.

Canonical record: SAP CAP npm supply chain 2026 on BreachHistory.

Sources: BleepingComputer, Aikido, Socket