Official SAP npm packages compromised to steal credentials
2026-04-30T07:23:28Z•b266a50a9eacdc2d064ab7b678466c88a30be880d0f1182b259e42bf30d70e9f
CISACVE-2026-3854GitHubMicrosoft TeamsOAuthQinglongRCERobloxSAPTeamPCPVercelWHMWindows zero-dayWordPressaccount takeoverauth-bypassbackdoorcPanelcredential theftcryptofraudcryptomininglaw-enforcementnpmransomware','wiper','VECT 2.0'supply-chain
What happened
A roundup of multiple active security incidents and disclosures: official SAP npm packages were compromised (suspected TeamPCP supply‑chain attack) to steal developer credentials and tokens; a popular WordPress redirect plugin (70k+ installs) contained a five‑year dormant backdoor allowing arbitrary code injection; Qinglong task scheduler is being exploited via two auth‑bypass/RCE flaws to deploy cryptominers; three suspects were arrested for hijacking and selling ~610,000 Roblox accounts; cPanel/WHM received an emergency fix for a critical authentication‑bypass vulnerability; European police拆
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- b266a50a9eacdc2d064ab7b678466c88a30be880d0f1182b259e42bf30d70e9f
- Enrichment time
- 2026-04-30T07:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.