npm

@cap-js/db-service

@cap-js/db-service is identified in the SafeDep analysis "Mini Shai Hulud and SAP Compromise". Four SAP npm packages published on April 29, 2026 contain a two-stage credential-stealing payload targeting GitHub tokens, AWS keys, and CI/CD pipelines. The packages share SAP-affiliated maintainers, pointing to a publisher account compromise.

discovered 2026-04-29

Threat types

credential_stealerdata_exfiltrationworm

Malicious versions

  • 2.10.1

Campaigns

Indicators

Techniques

Read the full analysis →