Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Four official SAP npm packages used in enterprise cloud application development were compromised with credential-harvesting code that executes automatically during routine software builds. Any organization that has installed @cap-js/sqlite v2.2.2, @cap-js/postgres v2.2.2, @cap-js/db-service v2.10.1, or mbt v1.2.48 is at risk of having cloud credentials, SSH keys, Kubernetes secrets, and CI/CD pipeline tokens silently stolen. The attack self-propagates by using stolen npm credentials to compromise additional packages, meaning the blast radius extends beyond the initial four packages.

Author

Tech Jacks Solutions