datadog-security-labs · Crawled Jul 18, 2026
Compromised AsyncAPI npm packages: inside a CI supply-chain attack
7 IoCs
Read original article ↗
AI Summary
A supply-chain attack compromised four popular npm packages under the @asyncapi namespace, affecting over 3 million weekly downloads. The attacker exploited a vulnerable CI pipeline via a malicious pull request to steal credentials for the asyncapi-bot GitHub account, then injected malicious code into the packages. The payloads exfiltrate developer credentials and persist via IDE configuration hooks, leveraging decentralized C2 infrastructure including IPFS and Nostr for resilience.
AI-extracted · verify before operational use