Vulnerabilities · 61 days ago
The dangerous moment is no longer package install. These poisoned AsyncAPI packages execute as soon as Node imports them, so a CI job, container build, or production service can be infected just by resolving a dependency that never ran an install script.
Microsoft says five republished versions are affected: @asyncapi/specs@6.11.2 and @asyncapi/specs@6.11.2-alpha.1, @asyncapi/generator@3.3.1, @asyncapi/generator-components@0.7.1, and @asyncapi/generator-helpers@1.1.1. The loader drops a second stage from IPFS and now resolves to a Miasma runtime with active C2 and persistence, which broadens the blast radius across developer workstations, CI/CD pipelines, container builds, and any runtime that imports these packages.
The standard `--ignore-scripts` defense does not help here because the trigger is module load, not an install hook. That makes any environment that imported the packages during the exposure window a live compromise candidate, even if it never executed npm scripts.
9 sources covering this story
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm.
NPM ecosystem hit with two new supply chain compromises
Stolen and leaked credentials lead to Node.js packages from AsyncAPI and Jscrambler Code Integrity being poisoned with malware.
AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised AsyncAPI npm packages load a multi-stage botnet from IPFS after attackers abuse GitHub Actions, despite valid provenance attestations
Ett koordinerat leveranskedjeangrepp har drabbat separata AsyncAPI GitHub-repon.
AsyncAPI Supply Chain Compromise via GitHub Actions | Wiz Blog
Detect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.
Compromised npm Packages in the AsyncAPI Namespace Deliver M...
4 compromised asyncapi packages deliver miasma botnet loader on macOS, Linux and Windows.
Compromised AsyncAPI npm packages: inside a CI supply-chain attack | Datadog Security Labs
On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware.
Miasma v3 Hits AsyncAPI: Is NPM Hardening Working?
Miasma v3 compromised 4 AsyncAPI npm packages using a load-time payload with worm capabilities deliberately disabled.
Part of the PlainSec briefing for 2026-07-16