SAP SE
Incident posture
Timeline
Summary
TeamPCP compromised four npm packages used in SAP's cloud application development ecosystem — @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service and mbt — by injecting malicious preinstall scripts that harvest developer and CI/CD secrets from GitHub, npm and major cloud providers and exfiltrate the data to attacker‑controlled GitHub repositories. The packages were removed after discovery. Analysis links the intrusion to TeamPCP through shared tactics such as a second‑stage payload that aborts on Russian‑language systems and the use of a common RSA public key to encrypt stolen data, while noting the campaign’s reference to the earlier Shai‑hulud worm is merely thematic. Similar attacks using the same toolkit have been observed on other ecosystems, including a lightning PyPI package and an Intercom npm package.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 30 2026 cybersecurity vendors Wiz Socket and Aikido Security identified four npm packages associated with SAP's Cloud Application Programming Model and Cloud MTA Build Tool that had been published with malicious preinstall scripts. The affected packages were @cap-js/sqlite version 2.2.2 @cap-js/postgres version 2.2.2 @cap-js/db-service version 2.10.1 and mbt version 1.2.48. Once installed the scripts executed a multistage payload designed to harvest developer and CI/CD secrets from GitHub npm and major cloud providers and exfiltrate the data to attacker‑controlled GitHub repositories. The malware contained the hard‑coded string 'A Mini Shai-Hulud has Appeared' as a reference to the Shai‑hulud worm campaigns that had targeted npm packages since September 2025. Socket researchers noted that the four packages had meaningful reach across the SAP developer ecosystem with hundreds of thousands of downloads per week. The poisoned packages were removed from the registry shortly after publication.
Analysis of the payload showed that the attack was attributed to the threat group TeamPCP based on overlapping tradecraft with its previous supply chain intrusions. The malware includes a second‑stage component that aborts data exfiltration if the infected system is configured for the Russian language. Past TeamPCP campaigns have used a shared RSA public key to encrypt stolen data and the Mini Shai‑Hulud samples employed the same key for encryption. Researchers emphasized that the reference to Shai‑hulud in the malware is merely a thematic nod and does not indicate a operational link to the earlier Shai‑hulud worm attacks which leaked secrets in the clear whereas this campaign encrypts the exfiltrated data. In earlier incidents TeamPCP has reused credentials stolen from one compromised package to gain access to other open‑source projects creating a cascading series of supply chain compromises.
Investigators have not determined definitively how the attackers gained the ability to publish the malicious versions but security engineer Adnan Khan hypothesized that an exposed npm token in the SAP/cloud-mta-build-tool repository due to a misconfigured CircleCI build provided the initial foothold. Aikido Security's researcher Raphael Silva said that the technical evidence aligns with Khan's theory while noting that the exposed token may not be the sole cause of the broader SAP incident. Separate research from Socket reported that the same tools and tradecraft observed in the Mini Shai‑Hulud campaign were also used in compromises of the lightning PyPI package and Intercom's npm package. Dark Reading contacted SAP for comment on the attacks but the company did not respond at press time. The packages were taken down soon after they were published limiting further installation.
Sources
Sources available to members: 1 source.