AsyncAPI npm Supply Chain Attack Deploys Miasma RAT via Compromised GitHub Actions
ID: 57d23bcc-979c-581d-8748-e1c30d7d97b0
STIX ID: report--57d23bcc-979c-581d-8748-e1c30d7d97b0
Feed Name: Cyber Press
AsyncAPI's npm ecosystem was compromised via vulnerable GitHub Actions workflows that allowed attackers to publish malicious releases under the project's legitimate npm namespace. The injected code delivered a Miasma-associated RAT that activated when affected modules were imported, launched a detached Node.js process, fetched an encrypted second stage from IPFS, and used an Ethereum smart contract and decentralized services for command-and-control updates, exposing developer endpoints, CI/CD runners, and build environments to credential theft and remote access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
