Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

In April 2026, the threat actor TeamPCP injected credential-stealing malware into npm packages with approximately 570,000 combined weekly downloads, compromising SAP Cloud Application Programming Model libraries, the Bitwarden CLI, and Checkmarx security tooling. The malware self-propagates by republishing infected package versions to npm, extending its reach across dependent CI/CD pipelines and cloud environments. Organizations using these toolchains face direct risk of cloud credential theft (AWS, Azure, GCP), Kubernetes secret exposure, and GitHub token compromise, enabling attackers to pivot into production infrastructure.

Author

Tech Jacks Solutions