ended4월 30일· 1 sources
Malicious SAP npm Packages Exploit CI Pipelines to Hijack Developer Credentials
SAP npm 패키지 해킹 사고... CI 파이프라인 악용한 공급망 공격 주의보
Why it matters
This supply chain attack demonstrates a sophisticated level of manipulation by hijacking SAP's CI/CD pipeline to bypass standard security checks and spread via developer environments. It highlights the critical need for verifying SLSA attestations and monitoring automated publishing workflows to prevent credential theft across major cloud platforms.
1
Sources
+0
24h
—
Growth
129d
Active
SAPnpmsupply chain attackCI/CD pipelineGitHub tokenOIDC