SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack
2026-04-30T01:24:20Z•ac1b1f41189e96cd58dc0cb7c5b6b070131875c4c21939ac337bbbedc74517a5
active-exploitationai-enabled-attacksbackdoorcisa-kevcredential-stealercvedprknpmransomwarercesoftware-vulnerabilitysql-injectionsupply-chainvscode-extensionswiper
What happened
A cluster of high-impact incidents and active campaigns reported by The Hacker News (late April 2026): multiple npm supply-chain compromises (including SAP-related packages) distributing credential-stealing malware and AI-inserted malicious dependencies; a DPRK-linked campaign leveraging AI/LLM tooling, fake companies and RATs; rapid in-the-wild exploitation of newly disclosed vulnerabilities (notably LiteLLM SQLi exploited within 36 hours and a GitHub RCE exploitable via a single git push); critical unauthenticated RCE in Hugging Face LeRobot; active exploitation of a Windows Shell spoofing/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ac1b1f41189e96cd58dc0cb7c5b6b070131875c4c21939ac337bbbedc74517a5
- Enrichment time
- 2026-04-30T01:24:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.