Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
ID: 9c40a4db-9033-55a6-a2de-b49a015bb075
STIX ID: report--9c40a4db-9033-55a6-a2de-b49a015bb075
Feed Name: Socket Blog
Executive Summary: Socket's Threat Research Team identified four compromised @asyncapi npm packages (published 2026-07-14) that include an obfuscated first-stage implant which spawns a detached node process to download an encrypted second-stage loader from IPFS; that loader decrypts and loads a Miasma-family tasking framework with persistent service behavior, multi-channel C2 (HTTP, IPFS, Nostr, DHT), and multiple IOCs (package names, tarball SHA-256s, IPFS CID, C2 IPs, persistence paths).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
