Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3747787
was released on
29.04.2026 and deals with
"3747787 - Malicious open-source packages in SAP Cloud Application Programming Model & MTA Build Tool" within BTP.
We advice you to follow the instructions, to resolve
remote code execution vulnerability
with a
hot news potential for exploitation
in component BC-XS-CDX-NJS.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
This note has been re-released with updated information. Malicious versions of four SAP Cloud Application Programming Model and MTA Build Tool npm packages distributed via the NPM ecosystem execute unauthorized code when installed on a developer system or CI/CD pipeline, resulting in credential exfiltration and propagation into adjacent software repositories.
Solution
Patched versions of the affected npm packages have been released and the malicious package versions have been removed from the NPM registry, preventing further distribution of the compromised packages.
