SecurityWeek A.I CyberSecurity Scoring
SecurityWeek
Company Information
Website:https://www.securityweek.com/
Employees number:10
Number of followers:7,276
NAICS:541514
Industry Type:Computer and Network Security
Homepage:securityweek.com
SecurityWeek Risk Score (AI oriented)
Between 700 and 749
SecurityWeekComputer and Network Security
Updated:
30/04/2026
30/04/2026
731/1000
Moderate
Ba
SecurityWeek Global Score (TPRM)
xxxx
SecurityWeekComputer and Network Security
Score locked

SecurityWeekModerate
Current Score
731Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
732
MAY 2026
732
APRIL 2026
748
Cyber Attack
01 Apr 2026 • SecurityWeek
Checkmarx, Trivy and SAP: Official SAP npm packages compromised to steal credentials
SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack
731
CRITICAL-17
CHESAPSEC1777508710
SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack
Security researchers have uncovered a supply-chain attack targeting multiple official SAP npm packages, believed to be orchestrated by the TeamPCP threat group. The compromise affected four packages @cap-js/sqlite (v2.2.2), @cap-js/postgres (v2.2.2), @cap-js/db-service (v2.10.1), and mbt (v1.2.48) which support SAP’s Cloud Application Programming Model (CAP) and Cloud MTA, widely used in enterprise development.
The malicious packages contained a preinstall script that executed automatically upon installation, deploying a loader (setup.mjs) to fetch the Bun JavaScript runtime from GitHub. This runtime then ran an obfuscated execution.js payload, designed to steal sensitive credentials from developer systems and CI/CD environments, including:
- npm and GitHub authentication tokens
- SSH keys and developer credentials
- Cloud credentials (AWS, Azure, Google Cloud)
- Kubernetes configurations and secrets
- CI/CD pipeline secrets and environment variables
On CI runners, the malware used an embedded Python script to scan process memory (/proc/\<pid\>/maps and /proc/\<pid\>/mem) for secrets, bypassing log masking a tactic identical to previous TeamPCP attacks, such as those targeting Bitwarden and Checkmarx.
Stolen data was encrypted and exfiltrated to public GitHub repositories under victims’ accounts, marked with the description "A Mini Shai-Hulud has Appeared" a reference mirroring the "Shai-Hulud: The Third Coming" string from earlier attacks. The malware also employed GitHub commit searches as a dead-drop mechanism, decoding commit messages containing base64-encoded tokens to escalate access.
Additionally, the payload included self-propagation capabilities, using stolen credentials to modify other accessible packages and repositories, further spreading the infection.
Researchers have linked the attack to TeamPCP with medium confidence, citing similarities in code and tactics to prior incidents involving Trivy, Checkmarx, and Bitwarden. While the exact compromise vector remains unclear, evidence suggests an exposed NPM token from a misconfigured CircleCI job may have been exploited.
SAP has not yet responded to inquiries regarding the breach. The affected package versions have since been deprecated on npm.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
748
FEBRUARY 2026
748
JANUARY 2026
748
DECEMBER 2025
748
NOVEMBER 2025
748
OCTOBER 2025
748
SEPTEMBER 2025
748
AUGUST 2025
748
JULY 2025
748
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SecurityWeek ??
What was SecurityWeek's A.I Rankiteo Cyber Score in May 2026 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in April 2026 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in March 2026 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in February 2026 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in January 2026 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in December 2025 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in November 2025 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in October 2025 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in September 2025 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in August 2025 ??
What was SecurityWeek's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on SecurityWeek's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SecurityWeek ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SecurityWeek's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?