Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Inside the AsyncAPI Supply Chain Compromise

released on 2026-08-27 @ 10:16:24 PM
In July 2026, Microsoft Threat Intelligence uncovered a supply chain attack targeting the official AsyncAPI NPM organization. Attackers published malicious versions of multiple packages under the trusted AsyncAPI namespace, exploiting developer dependencies to distribute malware. The compromised packages deployed a multi-stage Remote Access Trojan through obfuscated lifecycle hooks that executed during routine build workflows. Upon installation, the malware retrieved second-stage payloads from IPFS gateways, established persistence on infected systems, and initiated command-and-control communications with external infrastructure. The attack leveraged trusted build automation and dynamic package retrieval via npx to bypass traditional security controls, affecting developers executing version-pinned tasks in their CI/CD pipelines.