step-security · Crawled Jul 14, 2026
Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories
6 IoCs
Read original article ↗
AI Summary
A coordinated supply chain attack compromised two AsyncAPI GitHub repositories on July 14, 2026, by injecting malicious code into the CI/CD pipelines. The attacker gained push access to the 'next' and 'master' branches, leveraging legitimate GitHub Actions workflows to publish four malicious npm packages without stealing tokens. These packages delivered an obfuscated dropper that downloads and executes the Miasma RAT, a sophisticated payload with multi-channel C2 capabilities, credential harvesting, AI tool poisoning, and worm-like propagation features. The attack bypassed trust mechanisms like SLSA provenance by abusing authorized pipelines, highlighting risks in CI/CD security.
AI-extracted · verify before operational use