<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Official SAP npm Packages compromised to steal Credentials and Authentication Tokens from Developers Systems.]]></title><description><![CDATA[<p>Official SAP npm Packages compromised to steal Credentials and Authentication Tokens from Developers Systems.</p><p>Security researchers report that the compromise impacted four packages, with the versions now deprecated on NPM:</p><p>• @cap-js/sqlite – v2.2.2<br />• @cap-js/postgres – v2.2.2<br />• @cap-js/db-service – v2.10.1<br />• mbt – v1.2.48</p><p><img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2049.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--interrobang"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="⁉"
      alt="⁉"
    />️These packages support SAP's Cloud Application Programming Model [CAP] and Cloud MTA, which are commonly used in enterprise development.<img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2049.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--interrobang"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="⁉"
      alt="⁉"
    />️</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://socket.dev/blog/sap-cap-npm-packages-supply-chain-attack" title="TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MT...">
<img src="https://cdn.sanity.io/images/cgdhsj6q/production/cbda49159aaf9978478cc136ad6bfd82973a4244-1149x753.png?w=1000&q=95&fit=max&auto=format" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://socket.dev/blog/sap-cap-npm-packages-supply-chain-attack">
TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MT...
</a>
</h5>
<p class="card-text line-clamp-3">Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environ...</p>
</div>
<a href="https://socket.dev/blog/sap-cap-npm-packages-supply-chain-attack" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://socket.dev/favicon-32x32.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />









<p class="d-inline-block text-truncate mb-0">Socket <span class="text-secondary">(socket.dev)</span></p>
</a>
</div></p><p><a href="https://nerdculture.de/tags/sap" rel="tag">#<span>sap</span></a> <a href="https://nerdculture.de/tags/npmpackages" rel="tag">#<span>npmpackages</span></a> <a href="https://nerdculture.de/tags/secure" rel="tag">#<span>secure</span></a> <a href="https://nerdculture.de/tags/programming" rel="tag">#<span>programming</span></a> <a href="https://nerdculture.de/tags/developer" rel="tag">#<span>developer</span></a> <a href="https://nerdculture.de/tags/security" rel="tag">#<span>security</span></a> <a href="https://nerdculture.de/tags/privacy" rel="tag">#<span>privacy</span></a> <a href="https://nerdculture.de/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://nerdculture.de/tags/tech" rel="tag">#<span>tech</span></a> <a href="https://nerdculture.de/tags/news" rel="tag">#<span>news</span></a></p>

<div class="row mt-3"><img class="img-thumbnail" src="https://media.nerdculture.de/media_attachments/files/116/533/016/014/211/087/original/9e3b55957f2dfd7f.jpeg" alt="Link Preview Image" /><img class="img-thumbnail" src="https://media.nerdculture.de/media_attachments/files/116/533/016/568/352/923/original/7497e0643a8bc5a5.jpeg" alt="Link Preview Image" /></div>]]></description><link>https://board.circlewithadot.net/topic/3b85c049-1993-45c4-8227-cfc4bf482fde/official-sap-npm-packages-compromised-to-steal-credentials-and-authentication-tokens-from-developers-systems.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 06:18:02 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/3b85c049-1993-45c4-8227-cfc4bf482fde.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 07 May 2026 11:20:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Official SAP npm Packages compromised to steal Credentials and Authentication Tokens from Developers Systems. on Sat, 09 May 2026 09:28:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/olly42%40nerdculture.de">@<span>Olly42</span></a></span> Wait, are the compromised versions of those packages still available for download anywhere, or did npm fully pull them after they were deprecated?</p>]]></description><link>https://board.circlewithadot.net/post/https://social.vir.group/users/newsgroup/statuses/116543909049233210</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.vir.group/users/newsgroup/statuses/116543909049233210</guid><dc:creator><![CDATA[newsgroup@social.vir.group]]></dc:creator><pubDate>Sat, 09 May 2026 09:28:44 GMT</pubDate></item></channel></rss>