security1 publisher
Shai-Hulud's third wave printed SAP's npm token straight into a workflow log
Four core SAP build packages shipped an identical 11.6MB credential stealer. Because npm trusted the whole cap-js repository rather than one branch, a commit pushed to an unused branch was enough to publish them.
Publishers:stepsecurity.io
Reality
- Evidence60
- Adoption38
- Hype gap+15
- Incentives78
- Confidence55