logo

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

ID: bbc515a8-91ae-51f2-8973-63a0d0becb45

STIX ID: report--bbc515a8-91ae-51f2-8973-63a0d0becb45

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Microsoft Security Research, Ravikant Tiwari, Sagar Patil, Suriyaraj Natarajan and Arvind Gowda

...
...

Microsoft Threat Intelligence observed a coordinated supply-chain compromise of the @asyncapi npm organization on July 14, 2026: five package versions were republished with an import-time loader that spawns a detached Node.js process, fetches an encrypted ~8.2 MB Miasma runtime from IPFS, and installs persistence and C2 (85.137.53.71:8080/8081/8091). The attacker leveraged a misconfigured GitHub Actions pull_request_target workflow to steal a bot token and publish poisoned releases via legitimate OIDC workflows; mitigations include removing the affected package versions, purging caches, hunting for sync.js in NodeJS masquerade directories, blocking the listed C2/IPFS endpoints, and rotating exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.