logo

Hackers Abuse GitHub Actions to Backdoor AsyncAPI npm Packages With Miasma RAT

ID: 973c9bb9-308b-5705-95ab-e048bbfe0d82

STIX ID: report--973c9bb9-308b-5705-95ab-e048bbfe0d82

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Tushar Subhra Dutta

...
...

A supply-chain attack compromised AsyncAPI’s publishing automation—via a vulnerable GitHub Actions configuration—to release malicious npm package versions containing Miasma-related code that executes on module import, fetches an encrypted second-stage from IPFS, and provides remote-access capabilities; affected package versions, file names, an Ethereum contract, an IPFS CID, and related network signatures are provided as IoCs, and responders are advised to audit manifests/lockfiles, review outbound connections and repository logs, rotate credentials, and harden privileged workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.