• bitcoinBitcoin (BTC) $ 61,430.00
  • ethereumEthereum (ETH) $ 1,642.26
  • tetherTether (USDT) $ 0.998310
  • bnbBNB (BNB) $ 569.49
  • usd-coinUSDC (USDC) $ 0.999646
  • xrpXRP (XRP) $ 1.08
  • solanaSolana (SOL) $ 68.90
  • tronTRON (TRX) $ 0.329731
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • hyperliquidHyperliquid (HYPE) $ 63.26
  • dogecoinDogecoin (DOGE) $ 0.077058
  • usdsUSDS (USDS) $ 0.999569
  • rainRain (RAIN) $ 0.015913
  • leo-tokenLEO Token (LEO) $ 9.31
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 413.69
  • stellarStellar (XLM) $ 0.187840
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • whitebitWhiteBIT Coin (WBT) $ 50.05
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • canton-networkCanton (CC) $ 0.151963
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 314.07
  • chainlinkChainlink (LINK) $ 7.50
  • cardanoCardano (ADA) $ 0.149776
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • labLAB (LAB) $ 16.60
  • usd1-wlfiUSD1 (USD1) $ 0.998883
  • daiDai (DAI) $ 0.999715
  • susdssUSDS (SUSDS) $ 1.08
  • ethena-usdeEthena USDe (USDE) $ 0.998055
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.59
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • bitcoin-cashBitcoin Cash (BCH) $ 194.22
  • hedera-hashgraphHedera (HBAR) $ 0.074816
  • litecoinLitecoin (LTC) $ 41.79
  • wethWETH (WETH) $ 2,268.37
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • global-dollarGlobal Dollar (USDG) $ 0.999664
  • avalanche-2Avalanche (AVAX) $ 6.56
  • usdt0USDT0 (USDT0) $ 0.998824
  • suiSui (SUI) $ 0.690675
  • paypal-usdPayPal USD (PYUSD) $ 0.999928
  • shiba-inuShiba Inu (SHIB) $ 0.000004
  • crypto-com-chainCronos (CRO) $ 0.056600
  • nearNEAR Protocol (NEAR) $ 1.96
  • tether-goldTether Gold (XAUT) $ 3,977.90
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.14
  • bittensorBittensor (TAO) $ 219.54
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.060326
  • uniswapUniswap (UNI) $ 2.97
  • worldcoin-wldWorldcoin (WLD) $ 0.519283
  • pax-goldPAX Gold (PAXG) $ 3,979.12
  • mantleMantle (MNT) $ 0.508250
  • aster-2Aster (ASTER) $ 0.623723
  • okbOKB (OKB) $ 76.05
  • ripple-usdRipple USD (RLUSD) $ 0.999911
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • ondo-financeOndo (ONDO) $ 0.319488
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • htx-daoHTX DAO (HTX) $ 0.000002
  • polkadotPolkadot (DOT) $ 0.893334
  • falcon-financeFalcon USD (USDF) $ 0.993695
  • usddUSDD (USDD) $ 0.998798
  • pi-networkPi Network (PI) $ 0.126426
  • bfusdBFUSD (BFUSD) $ 0.997866
  • aaveAave (AAVE) $ 83.86
  • skySky (SKY) $ 0.054662
  • internet-computerInternet Computer (ICP) $ 2.23
  • bitget-tokenBitget Token (BGB) $ 1.68
  • morphoMorpho (MORPHO) $ 1.75
  • ethereum-classicEthereum Classic (ETC) $ 7.12
  • dexeDeXe (DEXE) $ 23.09
  • pepePepe (PEPE) $ 0.000003
  • united-stablesUnited Stables (U) $ 0.999405
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 68.61
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.03
  • kucoin-sharesKuCoin (KCS) $ 7.01
  • memecoreMemeCore (M) $ 0.697417
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.20
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • usdtbUSDtb (USDTB) $ 0.999693
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.12
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • stable-2​​Stable (STABLE) $ 0.036389
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • cosmosCosmos Hub (ATOM) $ 1.67
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • render-tokenRender (RENDER) $ 1.57
  • algorandAlgorand (ALGO) $ 0.090084
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • ethenaEthena (ENA) $ 0.085379
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.074102
  • wbnbWrapped BNB (WBNB) $ 759.61
  • kaspaKaspa (KAS) $ 0.028160
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • nexoNEXO (NEXO) $ 0.759144
  • jupiter-exchange-solanaJupiter (JUP) $ 0.226287
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.706319
  • justJUST (JST) $ 0.081916
  • gatechain-tokenGate (GT) $ 6.47
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • beldexBeldex (BDX) $ 0.084583
  • venice-tokenVenice Token (VVV) $ 13.34
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • flare-networksFlare (FLR) $ 0.006990
  • filecoinFilecoin (FIL) $ 0.758273
  • ghoGHO (GHO) $ 0.997630
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.14
  • xdce-crowd-saleXDC Network (XDC) $ 0.028696
  • yldsYLDS (YLDS) $ 0.999748
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.998840
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • adi-tokenADI (ADI) $ 4.38
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • aptosAptos (APT) $ 0.629232
  • midnight-3Midnight (NIGHT) $ 0.031343
  • audieraAudiera (BEAT) $ 1.79
  • clbtcclBTC (CLBTC) $ 76,920.00
  • usxUSX (USX) $ 0.999288
  • hash-2Provenance Blockchain (HASH) $ 0.009238
  • a7a5A7A5 (A7A5) $ 0.012650
  • true-usdTrueUSD (TUSD) $ 0.997493
  • aerodrome-financeAerodrome Finance (AERO) $ 0.513932
  • arbitrumArbitrum (ARB) $ 0.076974
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • pump-funPump.fun (PUMP) $ 0.001296
  • dashDash (DASH) $ 34.38
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • tbtctBTC (TBTC) $ 70,942.00
  • euro-coinEURC (EURC) $ 1.14
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.68
  • injective-protocolInjective (INJ) $ 4.25
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.31
  • lighterLighter (LIT) $ 1.66
  • official-trumpOfficial Trump (TRUMP) $ 1.72
  • hastra-primePRIME (PRIME) $ 1.04
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.176670
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • vechainVeChain (VET) $ 0.004615
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006156
  • sei-networkSei (SEI) $ 0.057403
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • bonkBonk (BONK) $ 0.000004
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.551880
  • cocaCOCA (COCA) $ 1.30
  • celestiaCelestia (TIA) $ 0.379751
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.996275
  • kite-2Kite (KITE) $ 0.149256
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000061
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • jito-governance-tokenJito (JTO) $ 0.688205
  • sun-tokenSun Token (SUN) $ 0.017125
  • ether-fiEther.fi (ETHFI) $ 0.350890
  • the9bitThe9bit (9BIT) $ 0.042627
  • blockstackStacks (STX) $ 0.175340
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • spx6900SPX6900 (SPX) $ 0.340725
  • apxusdapxUSD (APXUSD) $ 0.823391
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • kinesis-goldKinesis Gold (KAU) $ 129.80
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • grassGrass (GRASS) $ 0.491748
  • curve-dao-tokenCurve DAO (CRV) $ 0.195653
  • gnosisGnosis (GNO) $ 104.19
  • skyaiSkyAI (SKYAI) $ 0.275158
  • ethgas-2ETHGas (GWEI) $ 0.128754
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • pyth-networkPyth Network (PYTH) $ 0.033875
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • bittorrentBitTorrent (BTT) $ 0.00000027
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • apenftAINFT (NFT) $ 0.00000026
  • noonNoon (NOON) $ 0.751949
  • royal-dollarRoyal Dollar (RUSD) $ 0.998700
  • olympusOlympus (OHM) $ 16.16
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • plasmaPlasma (XPL) $ 0.092477
  • fraxLegacy Frax Dollar (FRAX) $ 0.990650
  • zebec-networkZebec Network (ZBCN) $ 0.002412
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • monadMonad (MON) $ 0.019872
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • tezosTezos (XTZ) $ 0.215698
  • optimismOptimism (OP) $ 0.108234
  • conflux-tokenConflux (CFX) $ 0.044283
  • msolMarinade Staked SOL (MSOL) $ 133.18

Malicious SAP npm packages target crypto wallet data

0 0


Four npm packages that were connected to SAP’s Cloud Application Programming Model were stolen. The hackers added code that steals crypto wallets, cloud credentials, and SSH keys from developers.

According to a report from Socket, the affected package versions include:

  • mbt@1.2.48.
  • @cap-js/db-service@2.10.1.
  • @cap-js/postgres@2.2.2.
  • @cap-js/sqlite@2.2.2.

These packages together get about 572,000 downloads a week from the SAP developer community.

npm packages steal cloud credentials and crypto wallets

Security researchers explained that the hacked packages pre-install a script that downloads and runs a Bun runtime binary from GitHub. It then runs an obfuscated 11.7MB JavaScript payload.

The original SAP source files are still there, but there are three additional new files:

  • a modified package.json.
  • setup.mjs.
  • execution.js.

These files were timestamped hours after the real code. This shows that the tarballs were changed after being downloaded from a real source.

Socket called it “a strong signal of a coordinated, automated injection campaign” that the loader script is byte-identical in all four packages, even though they are in two different namespaces.

When the payload runs, it checks if the system is set to Russian and stops if it is. It then branches depending on whether it finds a CI/CD environment, by checking 25 platform variables, such as GitHub Actions, CircleCI, and Jenkins, or a developer workstation.

On developer computers, the malware reads more than 80 different types of credential files. These include SSH private keys, AWS and Azure credentials, Kubernetes configs, npm and Docker tokens, environment files, and crypto wallets on eleven different platforms. It also goes after configuration files for AI tools like Claude and Kiro MCP settings.

The payload has two layers of encryption. A function called `__decodeScrambled()` uses PBKDF2 with 200,000 SHA-256 iterations and a salt called “ctf-scramble-v2” to get the keys needed to decrypt something.

SAP payloads use GitHub as the primary channel. Source: Socket.

The function name, algorithm, salt, and iteration count are the same as those in previous Checkmarx and Bitwarden payloads. This suggests that the same tools are being used in multiple campaigns.

Socket is keeping an eye on the activity under the name “TeamPCP” and has made a separate tracking page for what it calls the “mini-shai-hulud” campaign.

Hackers target crypto developers persistently

The SAP package compromise is the most recent in a series of supply chain attacks that use package managers to steal digital asset credentials.

As Cryptopolitan reported at the time, researchers found five typosquatted npm packages in March 2026 that stole private keys from Solana and Ethereum developers and sent them to a Telegram bot.

ReversingLabs found a campaign called PromptMink a month later. In this campaign, a malicious package called @validate-sdk/v2 was added to an open-source crypto trading project through an AI-generated commit.

Cryptopolitan’s coverage of the ReversingLabs findings says that the attack, which was linked to the North Korean state-sponsored group Famous Chollima, specifically went after crypto wallet credentials and system secrets.

The SAP attack is different in size and direction. Instead of making fake packages with names that are similar to real ones, the attackers got into real, widely used packages that were kept under SAP’s namespace.

Security researchers recommend that teams that use SAP CAP or MTA-based deployment pipelines check their lockfiles right away for the affected versions.

Developers who installed these packages during the exposure window should change any credentials and tokens that may have been available in their build environments and check CI/CD logs for any unexpected network requests or binary execution.

According to researchers, at least one affected version, @cap-js/sqlite@2.2.2, seems to have already been unpublished from npm.



Source link

Leave A Reply

Your email address will not be published.