logo

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

ID: ffdfae4a-4440-55fe-9fd8-af82b469c078

STIX ID: report--ffdfae4a-4440-55fe-9fd8-af82b469c078

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

Four @asyncapi npm packages were compromised and published via abuse of repository push credentials and legitimate GitHub Actions/OIDC release workflows; the malicious modules execute when required by Node.js, spawn a detached loader that downloads an encrypted second-stage JavaScript payload (Miasma) from IPFS, and establish a feature-rich command-and-control framework (HTTP, P2P, IPFS, BitTorrent DHT, Nostr, libp2p, Ethereum) that supports credential theft, lateral movement, persistence across OSes, and worm-like propagation. The malicious versions have been unpublished, but any environment that loaded or executed the affected versions should be treated as potentially compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.