GHSA-pvw4-cvr4-97p8
Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
Quick fix
GHSA-pvw4-cvr4-97p8 — @cap-js/sqlite: upgrade to the fixed version with the command below.
npm install @cap-js/sqlite@2.3.0Details
## Impact
On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were published. The malicious packages harvested credentials and attempted self-propagation. If a compromised version was installed, all credentials accessible on that machine (npm tokens, cloud provider credentials, SSH keys, GitHub PATs) should be considered compromised.
## Patches
Upgrade to `@cap-js/sqlite` >= 2.4.0, `@cap-js/postgres` >= 2.3.0, `@cap-js/db-service` >= 2.11.0. If a compromised version was ever installed, rotate all affected credentials.
## Workarounds
No workarounds.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/cap-js/cds-dbs/security/advisories/GHSA-pvw4-cvr4-97p8[WEB]
- https://github.com/cap-js/cds-dbs[PACKAGE]
- https://me.sap.com/notes/3747787[WEB]
- https://www.sap.com/documents/2026/05/8203a8b9-4d7f-0010-bca6-c68f7e60039b.html[WEB]
- https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared[WEB]