Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

On April 29, 2026, a threat actor published backdoored versions of four widely used SAP CAP framework npm packages, exploiting a GitHub Actions misconfiguration to bypass publishing controls and inject credential-harvesting malware. Organizations running SAP CAP-based applications face immediate risk of cloud credential theft across AWS, Azure, GCP, and Kubernetes environments, with over 1,100 exfiltration repositories observed before same-day patching. A persistence mechanism targeting AI coding agent configuration files (VS Code, Claude Code) means malicious instructions may survive package updates, extending the remediation window beyond simple dependency upgrades.

Author

Tech Jacks Solutions