MAL-2026-3179

    Dashboard / Malicious Package / MAL-2026-3179

    MAL-2026-3179

    Published: 29 Apr 2026Last Modified: 1 May 2026

    Summary: Malicious code in mbt (npm)

    Details: Supply chain compromise of legitimate SAP packages published by threat actor "[email protected]" impersonating SAP toolchain maintainers. All four compromised packages share the same fingerprint: setup.mjs (4.4 KB) and execution.js (11.1 MB) bundled in the tarball, with a preinstall hook of "node setup.mjs". Notably, setup.mjs is explicitly excluded from the package.json 'files' allowlist yet is still shipped in the tarball — a manifest evasion technique intended to hide the malicious file from allowlist inspection while still executing it on install. execution.js (11.1 MB) is anomalously large for these packages and is consistent with an embedded payload or exfiltration binary. Packages were published 2026-04-29T09:55Z. mbt (SAP Multi-Target Application Build Tool) is a high-impact CLI tool used in SAP CI/CD pipelines to compile and package MTA projects. Its privileged position in build environments makes it a valuable target for credential and token exfiltration. Source: amazon-inspector (62b15ba37c3071554cc586ba582589ad51abba89e1be51e993afdf933a18c8b1) The package mbt was found to contain malicious code.

    Affected packages

    Package

    Name: mbt

    Purl: pkg:npm/mbt

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.2.48