Official SAP npm packages compromised to steal credentials
BleepingComputer [Unofficial]
April 29, 2026
Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal credentials and authentication tokens from developers' systems. [...]
Discussion in the ATmosphere