⚠️ ALERT — SAP related npm packages were just found shipping credential-stealing malware. A preinstall script runs on install, steals tokens, and injects GitHub Actions to self-propagate, exfiltrating encrypted secrets via victim-owned repos. 🔗 Read → https://t.co/fPEIyIHdKi
