Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
ID: bbc515a8-91ae-51f2-8973-63a0d0becb45
STIX ID: report--bbc515a8-91ae-51f2-8973-63a0d0becb45
Feed Name: Microsoft Security
Date Published: 2026-07-16
Date Updated: 2026-07-16
Author: Microsoft Security Research, Ravikant Tiwari, Sagar Patil, Suriyaraj Natarajan and Arvind Gowda
Microsoft Threat Intelligence observed a coordinated supply-chain compromise of the @asyncapi npm organization on July 14, 2026: five package versions were republished with an import-time loader that spawns a detached Node.js process, fetches an encrypted ~8.2 MB Miasma runtime from IPFS, and installs persistence and C2 (85.137.53.71:8080/8081/8091). The attacker leveraged a misconfigured GitHub Actions pull_request_target workflow to steal a bot token and publish poisoned releases via legitimate OIDC workflows; mitigations include removing the affected package versions, purging caches, hunting for sync.js in NodeJS masquerade directories, blocking the listed C2/IPFS endpoints, and rotating exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
