Malicious SAP npm packages target crypto wallet data
A supply-chain attack compromised four SAP-linked npm packages ([email protected], @cap-js/[email protected], @cap-js/[email protected], @cap-js/[email protected]), inserting an obfuscated 11.7MB payload that steals crypto wallets, cloud credentials, SSH keys and CI/CD secrets. The packages receive roughly 572,000 downloads per week, expanding the scale and risk to developer workstations and build environments. Attackers used a Bun runtime loader and strong encryption (PBKDF2 with 200,000 SHA-256 iterations) and avoid Russian locales; researchers track the activity as “TeamPCP.” Market impact: stolen private keys and tokens could enable direct crypto theft and forced liquidations, increasing short-term sell pressure and raising security risk premiums for wallets, developer tooling and projects that rely on affected packages. Developers and teams using SAP CAP/MTA should audit lockfiles, rotate credentials and inspect CI/CD logs; at least one compromised version (@cap-js/[email protected]) was unpublished from npm.