As cited
Copy frozen at (site build).
threat intel
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four npm packages in the @asyncapi namespace were compromised and distributed a multi-stage botnet loader. The affected versions include @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, @asyncapi/generator@3.3.1, and @asyncapi/specs@6.11.2 and v6.11.2-alpha.1. Security firms OX Security, SafeDep, Socket, and StepSecurity identified the malicious activity.
Why it matters: Developers and organizations using these AsyncAPI packages face immediate risk of botnet infection; audit your npm dependencies for these specific versions and apply updates or removal as soon as possible.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four npm packages in the @asyncapi namespace were compromised to distribute a multi-stage botnet loader, according to security researchers from OX Security, SafeDep, Socket, and StepSecurity. The affected packages include @asyncapi/generator-helpers, @asyncapi/generator-components, @asyncapi/generator, and @asyncapi/specs at multiple versions.
Why it matters: Developers using these AsyncAPI packages are at risk of deploying botnet malware into their applications and environments; immediate verification of installed versions and installation of patched releases is necessary.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four npm packages in the @asyncapi namespace were compromised to distribute a multi-stage botnet loader, according to security researchers from OX Security, SafeDep, Socket, and StepSecurity. The affected packages include @asyncapi/generator-helpers, @asyncapi/generator-components, @asyncapi/generator, and @asyncapi/specs at multiple versions.
Why it matters: Developers using these AsyncAPI packages are at risk of deploying botnet malware into their applications and environments; immediate verification of installed versions and installation of patched releases is necessary.
- Source published
- First seen by Cybersecurity Tracker