logo

Cato CTRL™ Threat Brief: AsyncAPI Supply Chain Attack Delivers Miasma Malware Through Trusted npm Packages

ID: 29e7de04-bc30-5631-94b4-2c163fbc855a

STIX ID: report--29e7de04-bc30-5631-94b4-2c163fbc855a

Feed Name: Cato Networks

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-23

Author: Tal Biran

...
...

On July 14, 2026 attackers abused a vulnerable GitHub Actions workflow to push malicious changes into AsyncAPI’s release process and publish compromised versions of four widely used npm packages (combined ~2.9M weekly downloads). The injected code launched a detached Node.js process that fetched an encrypted second-stage Miasma RAT via IPFS and used an Ethereum contract as an updatable C2 configuration store, enabling persistence, remote execution, and credential theft across developer workstations, CI/CD runners, and build systems; the report provides indicators, timeline, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.