MIT TRACE

MIT CTL Logo
Back to Main Dashboard

SAP npm packages compromised in Mini Shai-Hulud software supply-chain attack

On 29 April 2026, malicious versions of four open-source packages associated with SAP's Cloud Application Programming Model and MTA build tooling were distributed through npm. SAP confirmed that the packages contained malware capable of exposing credentials and that anyone who downloaded the affected releases could have been impacted. Security analyses found credential-harvesting and self-propagation functionality capable of compromising developer environments and additional software repositories. Clean package versions replaced the malicious releases within hours, but the trusted SAP distribution channel had already been poisoned, creating a material software-supply-chain data-integrity impact.

74

Estimated severity

74 / 100

91

Source reliability

91 / 100

Approximate Date

29/04/2026

Targeted Company

SAP

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Germany

DEU

Other Affected Countries

No other affected countries reported

Target country

Germany

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalware

Attributed threat actors

TEAMPCP

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.