Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages
ID: 4c4de987-79d2-5407-acd7-cfca4666296c
STIX ID: report--4c4de987-79d2-5407-acd7-cfca4666296c
Feed Name: HackRead
Upwind investigated a coordinated supply-chain campaign that compromised multiple AsyncAPI npm repositories and publishing pipelines, publishing officially signed packages containing backdoored code. The attackers abused different release branches and OIDC publishing identities and used execution paths triggered during normal imports (rather than install scripts), increasing stealth and risk to developer workstations and CI/CD environments; Upwind recommends auditing dependency versions, pinning trusted releases, inspecting SBOMs/lockfiles, rotating exposed credentials, and adding runtime monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
