SAP-related npm packages were compromised in April 2026 in a credential-stealing supply chain attack. The mechanism follows the year’s established pattern; the context is what distinguishes it.
Organisations running enterprise resource planning software operate under change control, segregation of duties and audit regimes that have been refined for decades. The client-side components of that software arrive through the same public registry as any other JavaScript dependency.
Two Governance Regimes, One Artefact
The ERP platform itself is treated as critical: patched on a schedule, tested in staging, signed off. The npm packages that integrate with it are pulled by a build process, frequently with a version range rather than a pin, and typically without appearing in any change record at all.
Both practices are defensible in isolation. Together they mean the most heavily governed system in the organisation has a dependency path with no governance attached to it.
What The Credentials Reach
Credential theft from a build environment in this context is more consequential than the same theft elsewhere, because the pipelines that build ERP integrations tend to hold access to environments containing financial and personnel data.
The practical question for anyone running this stack is narrow and answerable: which credentials are readable from the pipeline that builds your ERP integrations, and what would they reach if published to a registry this afternoon?
Compiled from published reporting, listed below. Affected package lists are as published; we did not analyse samples. Corrections: corrections@forensicpost.com.