TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
Blog post from Socket
Socket is investigating a potential supply chain attack targeting several npm packages within SAP's JavaScript and cloud application development framework, notably affecting versions such as [email protected] and @cap-js/[email protected]. The compromised packages introduced a preinstall script that downloads and executes a Bun binary from GitHub, which was not part of the original package functionality, thereby posing a risk to developer and CI/CD environments. This attack is notable for its connection to SAP's Cloud Application Programming Model (CAP), used extensively for SAP cloud deployment, and has significant reach within the SAP developer ecosystem. The attack involves a sophisticated mechanism that includes obfuscated JavaScript payloads, credential theft from various sources, and abuse of GitHub for data exfiltration. Evidence suggests a link to the TeamPCP group, known for similar supply chain attacks, due to shared technical characteristics and operational patterns. Socket advises immediate review of dependency trees and security measures to mitigate potential exposure, as their research team continues to analyze the situation and provide updates.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Coding Assistant | 2 | 1,480 | 382 | 153 | +18% |
| Kubernetes | 2 | 2,306 | 381 | 103 | +25% |
| MCP | 2 | 6,108 | 613 | 170 | +36% |
| Secrets Management | 2 | 1,821 | 338 | 111 | +22% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.