As cited
Copy frozen at (site build).
threat intel
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
A supply chain attack targeted AsyncAPI npm packages through compromised GitHub Actions workflows. Malicious packages were distributed via npm, affecting developers who installed the compromised versions.
Why it matters: Developers using AsyncAPI packages need to identify and update to safe versions immediately, as the compromise could enable code execution in build pipelines and downstream applications.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
A supply chain attack targeted AsyncAPI npm packages through compromised GitHub Actions workflows. Malicious packages were distributed via npm, affecting developers who installed the compromised versions.
Why it matters: Developers using AsyncAPI packages need to identify and update to safe versions immediately, as the compromise could enable code execution in build pipelines and downstream applications.
- Source published
- First seen by Cybersecurity Tracker