BTCC / BTCC Square / Global Cryptocurrency /
Malicious SAP npm Packages Target Crypto Wallet Data in Coordinated Attack

Malicious SAP npm Packages Target Crypto Wallet Data in Coordinated Attack

Published:
2026-05-06 09:06:01
BTCCSquare news:

Security researchers uncovered a sophisticated malware campaign infiltrating SAP's developer ecosystem through compromised npm packages. The malicious versions—mbt@1.2.48, @cap-js/db-service@2.10.1, @cap-js/postgres@2.2.2, and @cap-js/sqlite@2.2.2—collectively receive over 572,000 weekly downloads, posing systemic risk to credential storage and cryptocurrency wallets.

The attack vector leverages obfuscated JavaScript payloads delivered via modified package files, including a byte-identical loader script across all compromised packages. Notably, the malware avoids Russian-language systems and adapts its behavior based on environment detection—targeting both CI/CD platforms and developer workstations. Credential theft spans SSH keys, cloud service tokens, and cryptocurrency wallet data.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users