
SAP npm Packages Hijacked to Steal Cloud Credentials and Weaponize AI Coding Agents
On 29 April 2026, four official npm packages from the SAP JavaScript and cloud application development ecosystem were compromised in a coordinated
Co-founder and CTO of RedRays

On 29 April 2026, four official npm packages from the SAP JavaScript and cloud application development ecosystem were compromised in a coordinated

We pointed our ABAP Code Scanner at a handful of production SAP systems over the past month. 30+ real vulnerabilities came out.

If you do SAP pentesting, you probably know pysap. It’s the only open-source library that lets you talk to SAP systems at

SAP has released its March 2026 security patch package containing 15 security notes addressing vulnerabilities across enterprise SAP environments. This release includes
Adding {{itemName}} to cart
Added {{itemName}} to cart