Official SAP npm packages compromised to steal credentials
2026-04-30T01:23:36Z•7322e31e963e40bd378e45fc013983c8b96e1c5b2bad94b6c0c183a642590997
CISASAPTeamPCPWHMaccount-theftauth-bypassbackdoorcPanelcredential-theftcryptomininggithublitellmnpmoauthpatchqinglongquick-page-post-redirectransomwarercerobloxsupply-chainvect-2.0vercelwindows-zero-daywordpress
What happened
Multiple high-impact security stories: official SAP npm packages were compromised in a suspected TeamPCP supply‑chain attack to steal developer credentials and tokens; a popular WordPress Quick Page/Post Redirect plugin contained a five‑year dormant backdoor for arbitrary code injection; Qinglong task scheduler is being exploited via authentication‑bypass RCEs to deploy cryptominers; attackers targeted LiteLLM via a critical pre‑auth SQLi (CVE‑2026‑42208). Additional notable items include arrests for mass Roblox account theft, an emergency cPanel/WHM auth‑bypass patch, CISA ordering federalrem
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 7322e31e963e40bd378e45fc013983c8b96e1c5b2bad94b6c0c183a642590997
- Enrichment time
- 2026-04-30T01:23:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.