IncidentFour Malicious Packages, One Missing Approval Gate
What Happened On April 29, 2026, attackers published malicious versions of four npm packages in the SAP development ecosystem. They exploited a CI pipeline vulnerability that allowed unauthorized npm














