logo

Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

ID: 9c40a4db-9033-55a6-a2de-b49a015bb075

STIX ID: report--9c40a4db-9033-55a6-a2de-b49a015bb075

Feed Name: Socket Blog

Threat Score
85/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: Socket Research Team

...
...

Executive Summary: Socket's Threat Research Team identified four compromised @asyncapi npm packages (published 2026-07-14) that include an obfuscated first-stage implant which spawns a detached node process to download an encrypted second-stage loader from IPFS; that loader decrypts and loads a Miasma-family tasking framework with persistent service behavior, multi-channel C2 (HTTP, IPFS, Nostr, DHT), and multiple IOCs (package names, tarball SHA-256s, IPFS CID, C2 IPs, persistence paths).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.