Compromised AsyncAPI npm packages: inside a CI supply-chain attack
ID: 77e227d3-0638-55bd-95cb-684b53b3f29e
STIX ID: report--77e227d3-0638-55bd-95cb-684b53b3f29e
Feed Name: Datadog Security Labs
On 2026-07-14, four widely used @asyncapi npm packages were backdoored after an attacker exploited a CI workflow (pull_request_target) to steal release credentials for the asyncapi-bot account and publish malicious package versions; the payload launches a Node.js second stage from IPFS that harvests and exfiltrates developer and cloud credentials to attacker-controlled servers (85.137.53.71) and uses cryptographic validation, decentralized fallback channels, and persistence mechanisms. Identifiers and huntable IOCs in the report include package versions (@asyncapi/[email protected], @asyncapi/[email protected], @asyncapi/[email protected], @asyncapi/[email protected][,-alpha.1]), the IPFS URL, Rentry paste, C2 IP and ports, local artifact (~/.cache/.sys_cache/.diag.enc), attacker public key, and an Ethereum contract address; organizations using those packages should assume potential compromise and investigate builds and developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
