AI & Tech

npm Supply-Chain Attack Backdoors AsyncAPI Packages With 2M Weekly Downloads

Attackers compromised the @asyncapi npm organization, publishing five malicious versions across four packages that together see over 2 million weekly downloads. The entry point was a misconfigured GitHub Actions workflow that leaked a bot’s access token. The nasty twist: the payload runs at import time, not install time — evading scanners that only check install scripts — and pulls a second-stage “Miasma” trojan from IPFS that steals browser passwords, SSH keys, npm and GitHub tokens, cloud credentials and crypto wallets. The poisoned versions (including @asyncapi/specs 6.11.2) are unpublished. If your lockfile touched them this week, rotate every credential.

Read the original — via Microsoft Security ↗

← All shorts