logo

AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads

ID: f1ee7aae-3614-5ac0-8371-4fddb1c790f1

STIX ID: report--f1ee7aae-3614-5ac0-8371-4fddb1c790f1

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

AsyncAPI npm packages (including @asyncapi/generator 3.3.1, @asyncapi/generator-components 0.7.1, @asyncapi/generator-helpers 1.1.1, and @asyncapi/specs 6.11.2/6.11.2-alpha.1) were compromised with a 91,973-line malicious payload that acts as a hybrid info-stealer, crypto-stealer and RAT; the malware uses IPFS and BitTorrent bootstrap nodes for resilient C2 (primary C2 observed at 85.137.53.71), checks for VM/EDR/Russian locale to evade analysis, can publish to npm/PyPI/Cargo if it finds credentials, and has an embedded Ethereum address, prompting urgent revocation of tokens, secret rotation, and audit of package releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.