As cited
Copy frozen at (site build).
threat intel
Compromised AsyncAPI npm packages: inside a CI supply-chain attack
Four npm packages in the @asyncapi namespace with over 3 million weekly downloads were compromised on July 14, 2026 to deliver credential-stealing malware. The attack targeted the continuous integration (CI) supply chain and affected a significant portion of the Node.js ecosystem. Developers using these packages may have exposed credentials through the malicious code.
Why it matters: Node.js developers and organizations using @asyncapi packages need to audit their environments immediately for signs of compromise and rotate any credentials that may have been exfiltrated by the malware.
- Source published
- First seen by Cybersecurity Tracker