Vulnerabilità · 75 giorni fa
La rottura è nel punto in cui molti team si sentono al sicuro: il caricamento del modulo, non solo l’installazione. Se un ambiente CI, un container di build o un servizio importa questi package, il loader parte subito e `npm install --ignore-scripts` non basta a fermarlo.
Microsoft conferma che cinque versioni repubblicate in quattro package dell’area AsyncAPI hanno lo stesso loader iniettato: @asyncapi/specs 6.11.2 e 6.11.2-alpha.1, @asyncapi/generator 3.3.1, @asyncapi/generator-components 0.7.1 e @asyncapi/generator-helpers 1.1.1. Le fonti indicano impatto su workstation di sviluppo, pipeline CI/CD, build di container e servizi in produzione che abbiano risolto e importato quelle versioni; il secondo stadio scarica e avvia un runtime Miasma con C2 e persistenza.
Il rischio resta più ampio del singolo package takedown: qualsiasi flusso che risolve dipendenze npm di terze parti a runtime può aver già eseguito il loader prima che la parte applicativa parta. In questa campagna, la difesa standard centrata sugli hook di installazione perde il trigger reale.
9 fonti che coprono questa storia
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm.
NPM ecosystem hit with two new supply chain compromises
Stolen and leaked credentials lead to Node.js packages from AsyncAPI and Jscrambler Code Integrity being poisoned with malware.
AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised AsyncAPI npm packages load a multi-stage botnet from IPFS after attackers abuse GitHub Actions, despite valid provenance attestations
Ett koordinerat leveranskedjeangrepp har drabbat separata AsyncAPI GitHub-repon.
AsyncAPI Supply Chain Compromise via GitHub Actions | Wiz Blog
Detect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.
Compromised npm Packages in the AsyncAPI Namespace Deliver M...
4 compromised asyncapi packages deliver miasma botnet loader on macOS, Linux and Windows.
Compromised AsyncAPI npm packages: inside a CI supply-chain attack | Datadog Security Labs
On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware.
Miasma v3 Hits AsyncAPI: Is NPM Hardening Working?
Miasma v3 compromised 4 AsyncAPI npm packages using a load-time payload with worm capabilities deliberately disabled.
Part of the PlainSec briefing for 2026-07-16