logo

Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages

ID: 4c4de987-79d2-5407-acd7-cfca4666296c

STIX ID: report--4c4de987-79d2-5407-acd7-cfca4666296c

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-07-14

Date Updated: 2026-07-16

Author: Owais Sultan

...
...

Upwind investigated a coordinated supply-chain campaign that compromised multiple AsyncAPI npm repositories and publishing pipelines, publishing officially signed packages containing backdoored code. The attackers abused different release branches and OIDC publishing identities and used execution paths triggered during normal imports (rather than install scripts), increasing stealth and risk to developer workstations and CI/CD environments; Upwind recommends auditing dependency versions, pinning trusted releases, inspecting SBOMs/lockfiles, rotating exposed credentials, and adding runtime monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.