Official SAP npm packages compromised to steal credentials

2026-04-30T07:23:28Zb266a50a9eacdc2d064ab7b678466c88a30be880d0f1182b259e42bf30d70e9f
CISACVE-2026-3854GitHubMicrosoft TeamsOAuthQinglongRCERobloxSAPTeamPCPVercelWHMWindows zero-dayWordPressaccount takeoverauth-bypassbackdoorcPanelcredential theftcryptofraudcryptomininglaw-enforcementnpmransomware','wiper','VECT 2.0'supply-chain

What happened

A roundup of multiple active security incidents and disclosures: official SAP npm packages were compromised (suspected TeamPCP supply‑chain attack) to steal developer credentials and tokens; a popular WordPress redirect plugin (70k+ installs) contained a five‑year dormant backdoor allowing arbitrary code injection; Qinglong task scheduler is being exploited via two auth‑bypass/RCE flaws to deploy cryptominers; three suspects were arrested for hijacking and selling ~610,000 Roblox accounts; cPanel/WHM received an emergency fix for a critical authentication‑bypass vulnerability; European police拆

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b266a50a9eacdc2d064ab7b678466c88a30be880d0f1182b259e42bf30d70e9f
Enrichment time
2026-04-30T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Official SAP npm packages compromised to steal credentials · Baitaphish