socket-dev · Crawled Jul 14, 2026
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
4 IoCs
Read original article ↗
AI Summary
A supply chain attack has compromised three npm packages in the @asyncapi namespace, including @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/generator. These packages deliver a multi-stage botnet loader known as Miasma, which downloads its second-stage payload from IPFS and establishes persistence on the victim's system. The malware supports command execution, credential harvesting, and evasion techniques, posing significant risk to development and CI environments.
AI-extracted · verify before operational use