ended4월 30일· 1 sources

Malicious SAP npm Packages Exploit CI Pipelines to Hijack Developer Credentials

SAP npm 패키지 해킹 사고... CI 파이프라인 악용한 공급망 공격 주의보

Why it matters

This supply chain attack demonstrates a sophisticated level of manipulation by hijacking SAP's CI/CD pipeline to bypass standard security checks and spread via developer environments. It highlights the critical need for verifying SLSA attestations and monitoring automated publishing workflows to prevent credential theft across major cloud platforms.

1
Sources
+0
24h
Growth
129d
Active
SAPnpmsupply chain attackCI/CD pipelineGitHub tokenOIDC

Sources

Related Issues