Cato CTRL™ Threat Brief: AsyncAPI Supply Chain Attack Delivers Miasma Malware Through Trusted npm Packages
ID: 29e7de04-bc30-5631-94b4-2c163fbc855a
STIX ID: report--29e7de04-bc30-5631-94b4-2c163fbc855a
Feed Name: Cato Networks
On July 14, 2026 attackers abused a vulnerable GitHub Actions workflow to push malicious changes into AsyncAPI’s release process and publish compromised versions of four widely used npm packages (combined ~2.9M weekly downloads). The injected code launched a detached Node.js process that fetched an encrypted second-stage Miasma RAT via IPFS and used an Ethereum contract as an updatable C2 configuration store, enabling persistence, remote execution, and credential theft across developer workstations, CI/CD runners, and build systems; the report provides indicators, timeline, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
