Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3747787
was released on
29.04.2026 and deals with
"3747787 - Malicious open-source packages in SAP Cloud Application Programming Model & MTA Build Tool" within BTP.
We advice you to follow the instructions, to resolve
remote code execution vulnerability
with a
hot news potential for exploitation
in component BC-XS-CDX-NJS.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
Malicious versions of four SAP Cloud Application Programming Model (CAP) and MTA Build Tool npm packages distributed through the npm ecosystem execute unauthorized code upon installation on developer workstations or within CI/CD pipelines. This behavior can lead to credential exfiltration and further propagation into adjacent software repositories.
Solution
Patched versions of the affected npm packages have been released, and the malicious package versions have been removed from the npm registry, preventing any further distribution of the compromised packages.
