CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

​ ​AsyncAPI npm packages infected with credential-stealing malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2592

As cited

Copy frozen at (site build).

threat intel

​ ​AsyncAPI npm packages infected with credential-stealing malware

Five malicious versions of AsyncAPI packages were published to npm in a supply-chain attack, delivering a remote access trojan capable of stealing information. The attack targeted developers who installed the compromised packages during the incident window. This represents a direct threat to the software supply chain used by organizations that depend on npm dependencies.

Why it matters: Developers and organizations using AsyncAPI packages need to audit npm installations and update to patched versions immediately, as the malware provides attackers with remote access and credential harvesting capabilities on affected systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary