Junglewise Threat Intelligence

SAP @cap-js/openapi supply chain compromise

Severity: low · CVSS 3.1 · Published 2026-06-04

Vendors: SAP, npm.

Executive brief

A malicious version of @cap-js/openapi, an open-source library used by developers to build APIs, was published and automatically installed by applications depending on it. The compromised code harvested sensitive credentials (API tokens, cloud keys, SSH keys, GitHub tokens) from developer machines and attempted to propagate to other systems. Any organization that installed the affected version must treat all stored credentials as compromised and rotate them immediately.

Technical details

This is a supply chain compromise involving CWE-506 (embedded malicious code) in version 1.4.1 of the npm package @cap-js/openapi, published on May 19, 2026. The malicious payload harvested credentials accessible on the infected machine and attempted self-propagation to compromise additional systems. The attack is network-reachable and requires no authentication—exploitation occurs automatically upon package installation as a dependency during npm install operations. The vulnerability affects version 1.4.1 specifically, with a patch available in version 1.4.2 and later. Beyond upgrading, all credentials that were accessible on any machine where the compromised version was installed must be rotated.

Affected products

  • SAP @cap-js/openapi 1.4.1

Timeline

  • 2026-05-19: disclosed: Malicious version 1.4.1 published
  • 2026-06-04: patched: Patch released as version 1.4.2

References

Related threats