Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
Reported 30 Apr 2026 by otx · Severity: medium
Multiple npm packages in the SAP JavaScript and cloud application development ecosystem were compromised in a suspected supply chain attack. Affected packages include mbt@1.2.48, @cap-js/db-service@2.10.1, @cap-js/postgres@2.2.2, and @cap-js/sqlite@2.2.2. The compromised versions