logo

AsyncAPI npm packages backdoored via GitHub Actions

ID: 1ac864d8-2cfa-510a-b97f-a2560d0f0871

STIX ID: report--1ac864d8-2cfa-510a-b97f-a2560d0f0871

Feed Name: Aikido Security's Blog

Threat Score
90/100

Date Published: 2026-07-14

Date Updated: 2026-07-24

...
...

A supply-chain compromise published on 2026-07-14 trojanized five @asyncapi npm packages (notably @asyncapi/specs) after an attacker abused a pull_request_target GitHub Actions workflow to steal an npm token; importing the compromised modules spawns an obfuscated downloader that fetches encrypted Node.js loaders from IPFS and deploys a persistent implant (self-labelled M-RED-TEAM) providing a remote shell, persistence, beaconing to HTTP C2, and extensive credential-harvesting and propagation code (some features disabled in this seed). Indicators, persistence paths, C2 IP/ports, affected package versions, and remediation steps (downgrade/remove compromised versions, rotate secrets, hunt for drops and connections) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.