Germany
DEU
On 29 April 2026, malicious versions of four open-source packages associated with SAP's Cloud Application Programming Model and MTA build tooling were distributed through npm. SAP confirmed that the packages contained malware capable of exposing credentials and that anyone who downloaded the affected releases could have been impacted. Security analyses found credential-harvesting and self-propagation functionality capable of compromising developer environments and additional software repositories. Clean package versions replaced the malicious releases within hours, but the trusted SAP distribution channel had already been poisoned, creating a material software-supply-chain data-integrity impact.
Estimated severity
74 / 100
Source reliability
91 / 100
Approximate Date
29/04/2026
Targeted Company
SAP
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Germany
DEU
No other affected countries reported
Target country
Germany
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone