CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2552

As cited

Copy frozen at (site build).

threat intel

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four npm packages in the @asyncapi namespace were compromised and distributed a multi-stage botnet loader. The affected versions include @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, @asyncapi/generator@3.3.1, and @asyncapi/specs@6.11.2 and v6.11.2-alpha.1. Security firms OX Security, SafeDep, Socket, and StepSecurity identified the malicious activity.

Why it matters: Developers and organizations using these AsyncAPI packages face immediate risk of botnet infection; audit your npm dependencies for these specific versions and apply updates or removal as soon as possible.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four npm packages in the @asyncapi namespace were compromised to distribute a multi-stage botnet loader, according to security researchers from OX Security, SafeDep, Socket, and StepSecurity. The affected packages include @asyncapi/generator-helpers, @asyncapi/generator-components, @asyncapi/generator, and @asyncapi/specs at multiple versions.

Why it matters: Developers using these AsyncAPI packages are at risk of deploying botnet malware into their applications and environments; immediate verification of installed versions and installation of patched releases is necessary.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four npm packages in the @asyncapi namespace were compromised to distribute a multi-stage botnet loader, according to security researchers from OX Security, SafeDep, Socket, and StepSecurity. The affected packages include @asyncapi/generator-helpers, @asyncapi/generator-components, @asyncapi/generator, and @asyncapi/specs at multiple versions.

Why it matters: Developers using these AsyncAPI packages are at risk of deploying botnet malware into their applications and environments; immediate verification of installed versions and installation of patched releases is necessary.

VendorsGitHubMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary