Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
ID: ffdfae4a-4440-55fe-9fd8-af82b469c078
STIX ID: report--ffdfae4a-4440-55fe-9fd8-af82b469c078
Feed Name: The Hacker News
Four @asyncapi npm packages were compromised and published via abuse of repository push credentials and legitimate GitHub Actions/OIDC release workflows; the malicious modules execute when required by Node.js, spawn a detached loader that downloads an encrypted second-stage JavaScript payload (Miasma) from IPFS, and establish a feature-rich command-and-control framework (HTTP, P2P, IPFS, BitTorrent DHT, Nostr, libp2p, Ethereum) that supports credential theft, lateral movement, persistence across OSes, and worm-like propagation. The malicious versions have been unpublished, but any environment that loaded or executed the affected versions should be treated as potentially compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
