SAP Software Supply Chain Breached

SAP npm packages compromised in supply chain attack. Developer credentials & tokens stolen. Evidence suggests self-propagation.

Lauren Collins ·

SAP Software Supply Chain Breached

Multiple official SAP npm packages were compromised, leading to the theft of credentials and authentication tokens from developer systems. This incident is attributed to a supply-chain attack.

Four specific packages were impacted: `@cap-js/sqlite` v2. 2.2, `@cap-js/postgres` v2. 2.2, `@cap-js/db-service` v2. 10.1, and `mbt` v1. 2.48. These packages support SAP's Cloud Application Programming Model (CAP) and Cloud MTA, widely used in enterprise development.

The compromise involved modifying packages with a malicious 'preinstall' script that executed upon installation. This script downloaded and ran an obfuscated payload designed to steal various credentials.

Stolen data included npm and GitHub authentication tokens, SSH keys, cloud credentials for AWS, Azure, and Google Cloud, Kubernetes configurations, and CI/CD pipeline secrets. The malware also extracted secrets directly from CI runner memory, bypassing log masking.

Collected data was encrypted and uploaded to public GitHub repositories under the victim's account. The malware also utilized GitHub commit searches as a dead-drop mechanism to retrieve additional tokens and gain further access.

The deployed payload contained code for self-propagation, attempting to modify other packages and repositories using stolen credentials. This allowed for the injection of the same malicious code to spread the compromise.

This attack shows similarities to previous supply-chain incidents, with researchers linking it to a known threat actor group. The method of initial compromise for SAP's npm publishing process remains under investigation, though a misconfigured CircleCI job exposing an NPM token is a potential vector.

More stories

Latest news