datadog-security-labs · Crawled Jul 18, 2026

Compromised AsyncAPI npm packages: inside a CI supply-chain attack

7 IoCs
Read original article ↗

AI Summary

A supply-chain attack compromised four popular npm packages under the @asyncapi namespace, affecting over 3 million weekly downloads. The attacker exploited a vulnerable CI pipeline via a malicious pull request to steal credentials for the asyncapi-bot GitHub account, then injected malicious code into the packages. The payloads exfiltrate developer credentials and persist via IDE configuration hooks, leveraging decentralized C2 infrastructure including IPFS and Nostr for resilience.

AI-extracted · verify before operational use

Indicators of Compromise 7 extracted

Type Value Detail
IP 85[.]137[.]53[.]71 Details →
Domain ipfs[.]io Details →
SHA-256 qmqobzsp1wrprpseq56qnyq7eczh5bg5k1fnjt4suwwhb9 Details →
Filename sync.js Details →
Filename ~/.cache/.sys_cache/.diag.enc Details →
GitHub User elzotebo999 Details →
Registry User asyncapi-bot Details →