M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
ID: c101905f-7399-5f56-ad9c-f2318063b8c2
STIX ID: report--c101905f-7399-5f56-ad9c-f2318063b8c2
Feed Name: Wiz Blog
On July 14, 2026, an attacker opened malicious pull requests and exploited a GitHub Actions 'pull_request_target' workflow misconfiguration in the asyncapi/generator repository to steal a privileged asyncapi-bot PAT; using that token the attacker published five malicious @asyncapi npm package versions which execute a multi-stage payload on import, retrieve an encrypted stage from IPFS, persist across platforms (systemd service on Linux), and implement a modular command-and-control infostealer framework that harvests browser credentials, SSH keys, cloud and crypto credentials and communicates over HTTP, Nostr, Ethereum contracts, and libp2p. The report includes IOCs (file hashes, IPs, IPFS hashes, Ethereum addresses, filenames, service names and domains) and recommends rotating secrets, enhancing supply chain defenses, and applying package/blocklist detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
