Supply chain attacks spread... SAP, Intercom, and PyPI Lightning packages also affected

TL;DR AI
2 min readKey summary
Attackers reportedly compromised widely used developer packages from SAP, Intercom, and Lightning in a supply-chain attack.
The malicious packages encrypted stolen credentials and sent them to external servers, targeting cloud and source-control secrets.
Exposed data may include GitHub passwords, AWS access keys, Google Cloud credentials, and database credentials.
SAP has notified customers and partners about the incident.



