Supply-chain compromise: malicious @cap-js/[email protected] harvested credentials and self-propagated (GHSA-jpvj-wpmj-h7rv, CVSS 9.6)
On May 19 a compromised @cap-js/[email protected] (an SAP CAP framework plugin) was published to npm; today's advisory (CVSS 9.6) confirms it harvested every credential reachable on the install host — npm tokens, cloud provider keys, SSH keys, GitHub PATs — and attempted to self-propagate. This is the second confirmed self-propagating npm worm on the page today: same payload goal as IronWorm, different package, and it has been live for over two weeks. Upgrade to @cap-js/openapi >= 1.4.2, and if 1.4.1 ever touched a developer machine or CI runner, treat every credential on it as burned and rotate now — npm tokens and cloud keys first.