Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Official SAP npm Packages compromised to steal Credentials and Authentication Tokens from Developers Systems.

Official SAP npm Packages compromised to steal Credentials and Authentication Tokens from Developers Systems.

Scheduled Pinned Locked Moved Uncategorized
sapnpmpackagessecureprogrammingdeveloper
2 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • olly42@nerdculture.deO This user is from outside of this forum
    olly42@nerdculture.deO This user is from outside of this forum
    olly42@nerdculture.de
    wrote last edited by
    #1

    Official SAP npm Packages compromised to steal Credentials and Authentication Tokens from Developers Systems.

    Security researchers report that the compromise impacted four packages, with the versions now deprecated on NPM:

    • @cap-js/sqlite – v2.2.2
    • @cap-js/postgres – v2.2.2
    • @cap-js/db-service – v2.10.1
    • mbt – v1.2.48

    ⁉️These packages support SAP's Cloud Application Programming Model [CAP] and Cloud MTA, which are commonly used in enterprise development.⁉️

    Link Preview Image
    TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MT...

    Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environ...

    favicon

    Socket (socket.dev)

    #sap #npmpackages #secure #programming #developer #security #privacy #infosec #tech #news

    Link Preview ImageLink Preview Image
    newsgroup@social.vir.groupN 1 Reply Last reply
    0
    • olly42@nerdculture.deO olly42@nerdculture.de

      Official SAP npm Packages compromised to steal Credentials and Authentication Tokens from Developers Systems.

      Security researchers report that the compromise impacted four packages, with the versions now deprecated on NPM:

      • @cap-js/sqlite – v2.2.2
      • @cap-js/postgres – v2.2.2
      • @cap-js/db-service – v2.10.1
      • mbt – v1.2.48

      ⁉️These packages support SAP's Cloud Application Programming Model [CAP] and Cloud MTA, which are commonly used in enterprise development.⁉️

      Link Preview Image
      TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MT...

      Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environ...

      favicon

      Socket (socket.dev)

      #sap #npmpackages #secure #programming #developer #security #privacy #infosec #tech #news

      Link Preview ImageLink Preview Image
      newsgroup@social.vir.groupN This user is from outside of this forum
      newsgroup@social.vir.groupN This user is from outside of this forum
      newsgroup@social.vir.group
      wrote last edited by
      #2

      @Olly42 Wait, are the compromised versions of those packages still available for download anywhere, or did npm fully pull them after they were deprecated?

      1 Reply Last reply
      1
      0
      • R relay@relay.publicsquare.global shared this topic
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups