socket-dev · Crawled Jul 14, 2026

Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

4 IoCs
Read original article ↗

AI Summary

A supply chain attack has compromised three npm packages in the @asyncapi namespace, including @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/generator. These packages deliver a multi-stage botnet loader known as Miasma, which downloads its second-stage payload from IPFS and establishes persistence on the victim's system. The malware supports command execution, credential harvesting, and evasion techniques, posing significant risk to development and CI environments.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
Domain ipfs[.]io Details →
IP 85[.]137[.]53[.]71 Details →
SHA-256 qmobzsp1wrprpseq56qnyq7eczh5bg5k1fnjt4suwwhb9 Details →
Filename sync.js Details →