Intel Node
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery appeared first on Microsoft Security Blog .
In this article Attack chain overview How the attack started: GitHub Actions pwn request Mitigation and protection guidance Learn more On July 14, 2026, Microsoft Threat Intelligence identified a coordinated supply chain compromise of the @asyncapi npm organization, a widely used set of packages for the AsyncAPI specification and code generation. Five package versions across four package names were republished within roughly ninety minutes, each carrying the same maliciously injected loader: @asyncapi/specs (in both the 6. 11. 2-alpha. 1 prerelease and 6. 11. 2 stable release), @asyncapi/generator@3. 3. 1, @asyncapi/generator-components@0.
7. 1, and @asyncapi/generator-helpers@1. 1. 1.