logo

AsyncAPI npm Supply Chain Attack Deploys Miasma RAT via Compromised GitHub Actions

ID: 57d23bcc-979c-581d-8748-e1c30d7d97b0

STIX ID: report--57d23bcc-979c-581d-8748-e1c30d7d97b0

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Varshini

...
...

AsyncAPI's npm ecosystem was compromised via vulnerable GitHub Actions workflows that allowed attackers to publish malicious releases under the project's legitimate npm namespace. The injected code delivered a Miasma-associated RAT that activated when affected modules were imported, launched a detached Node.js process, fetched an encrypted second stage from IPFS, and used an Ethereum smart contract and decentralized services for command-and-control updates, exposing developer endpoints, CI/CD runners, and build environments to credential theft and remote access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.