As cited
Copy frozen at (site build).
threat intel
AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to npm in a supply-chain attack, delivering a remote access trojan capable of stealing information. The attack targeted developers who installed the compromised packages during the incident window. This represents a direct threat to the software supply chain used by organizations that depend on npm dependencies.
Why it matters: Developers and organizations using AsyncAPI packages need to audit npm installations and update to patched versions immediately, as the malware provides attackers with remote access and credential harvesting capabilities on affected systems.
- Source published
- First seen by Cybersecurity Tracker