bleeping-computer · Crawled Jul 15, 2026

​ ​AsyncAPI npm packages infected with credential-stealing malware

1 IoCs 1 Malware
Read original article ↗

AI Summary

Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack that delivered a credential-stealing remote access trojan. The attacker compromised GitHub repositories via a misconfigured CI/CD pipeline, leveraging legitimate workflows to publish trojanized packages with valid SLSA attestations. The malware, which resembles the Miasma backdoor, steals credentials, tokens, browser data, and other sensitive information, and communicates via HTTP, Nostr, Ethereum smart contracts, and libp2p. The exposure window lasted about four hours on July 14, 2026, and although the packages have been removed, existing installations may still be compromised.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Filename NodeJS/sync.js Details →

MITRE ATT&CK TTPs 6 techniques