logo

M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions

ID: c101905f-7399-5f56-ad9c-f2318063b8c2

STIX ID: report--c101905f-7399-5f56-ad9c-f2318063b8c2

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2026-07-14

Date Updated: 2026-07-23

Author: Rami McCarthy

...
...

On July 14, 2026, an attacker opened malicious pull requests and exploited a GitHub Actions 'pull_request_target' workflow misconfiguration in the asyncapi/generator repository to steal a privileged asyncapi-bot PAT; using that token the attacker published five malicious @asyncapi npm package versions which execute a multi-stage payload on import, retrieve an encrypted stage from IPFS, persist across platforms (systemd service on Linux), and implement a modular command-and-control infostealer framework that harvests browser credentials, SSH keys, cloud and crypto credentials and communicates over HTTP, Nostr, Ethereum contracts, and libp2p. The report includes IOCs (file hashes, IPs, IPFS hashes, Ethereum addresses, filenames, service names and domains) and recommends rotating secrets, enhancing supply chain defenses, and applying package/blocklist detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.