SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack

2026-04-30T01:24:20Zac1b1f41189e96cd58dc0cb7c5b6b070131875c4c21939ac337bbbedc74517a5
active-exploitationai-enabled-attacksbackdoorcisa-kevcredential-stealercvedprknpmransomwarercesoftware-vulnerabilitysql-injectionsupply-chainvscode-extensionswiper

What happened

A cluster of high-impact incidents and active campaigns reported by The Hacker News (late April 2026): multiple npm supply-chain compromises (including SAP-related packages) distributing credential-stealing malware and AI-inserted malicious dependencies; a DPRK-linked campaign leveraging AI/LLM tooling, fake companies and RATs; rapid in-the-wild exploitation of newly disclosed vulnerabilities (notably LiteLLM SQLi exploited within 36 hours and a GitHub RCE exploitable via a single git push); critical unauthenticated RCE in Hugging Face LeRobot; active exploitation of a Windows Shell spoofing/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ac1b1f41189e96cd58dc0cb7c5b6b070131875c4c21939ac337bbbedc74517a5
Enrichment time
2026-04-30T01:24:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.