hacker-news · Crawled Jul 15, 2026

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

3 IoCs
Read original article ↗

AI Summary

Four compromised npm packages under the @asyncapi namespace have been used to distribute a multi-stage botnet loader that downloads the Miasma malware from IPFS. The malicious code executes when the package is loaded via require(), not during install, evading traditional detection. The malware supports multiple C2 channels, enables credential theft, lateral movement, and includes a dead man's switch. The attack leveraged compromised CI/CD pipelines with legitimate OIDC attestations, not stolen npm tokens.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Domain ipfs[[.]]io Details →
IP ipfs[.]io Details →
Filename sync.js Details →