Desk live·
ForensicPost
Cloud/Supply chain/File 26-0408

Enterprise Packages, Consumer Registry, No Separation

SAP-related npm packages were compromised in a credential-stealing supply chain attack in April 2026. Enterprise software ships through the same public registry as everything else, with the same publishing controls.

Constructed geometry · not a chart of case data
TargetSAP-related npm packages
ActorUnattributed
D. Kennedy8 min readConfidence: high1 source reviewed

SAP-related npm packages were compromised in April 2026 in a credential-stealing supply chain attack. The mechanism follows the year’s established pattern; the context is what distinguishes it.

Organisations running enterprise resource planning software operate under change control, segregation of duties and audit regimes that have been refined for decades. The client-side components of that software arrive through the same public registry as any other JavaScript dependency.

Two Governance Regimes, One Artefact

The ERP platform itself is treated as critical: patched on a schedule, tested in staging, signed off. The npm packages that integrate with it are pulled by a build process, frequently with a version range rather than a pin, and typically without appearing in any change record at all.

Both practices are defensible in isolation. Together they mean the most heavily governed system in the organisation has a dependency path with no governance attached to it.

What The Credentials Reach

Credential theft from a build environment in this context is more consequential than the same theft elsewhere, because the pipelines that build ERP integrations tend to hold access to environments containing financial and personnel data.

The practical question for anyone running this stack is narrow and answerable: which credentials are readable from the pipeline that builds your ERP integrations, and what would they reach if published to a registry this afternoon?

How we reported this

Compiled from published reporting, listed below. Affected package lists are as published; we did not analyse samples. Corrections: corrections@forensicpost.com.

Sources
  1. SAP-related npm packages compromised in credential-stealing supply chain attackThe Hacker News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary