logo

Compromised AsyncAPI npm packages: inside a CI supply-chain attack

ID: 77e227d3-0638-55bd-95cb-684b53b3f29e

STIX ID: report--77e227d3-0638-55bd-95cb-684b53b3f29e

Feed Name: Datadog Security Labs

Threat Score
88/100

Date Published: 2026-07-14

Date Updated: 2026-07-23

...
...

On 2026-07-14, four widely used @asyncapi npm packages were backdoored after an attacker exploited a CI workflow (pull_request_target) to steal release credentials for the asyncapi-bot account and publish malicious package versions; the payload launches a Node.js second stage from IPFS that harvests and exfiltrates developer and cloud credentials to attacker-controlled servers (85.137.53.71) and uses cryptographic validation, decentralized fallback channels, and persistence mechanisms. Identifiers and huntable IOCs in the report include package versions (@asyncapi/[email protected], @asyncapi/[email protected], @asyncapi/[email protected], @asyncapi/[email protected][,-alpha.1]), the IPFS URL, Rentry paste, C2 IP and ports, local artifact (~/.cache/.sys_cache/.diag.enc), attacker public key, and an Ethereum contract address; organizations using those packages should assume potential compromise and investigate builds and developer endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.