1mo ago · hacker-news
Four compromised npm packages under the @asyncapi namespace have been used to distribute a multi-stage botnet loader that downloads the Miasma malware from IPFS. The malicious code executes when the package is loaded via require(), not during install, evading traditional detection. The malware supports multiple C2 channels, enables credential theft, lateral movement, and includes a dead man's switch. The attack leveraged compromised CI/CD pipelines with legitimate OIDC attestations, not stolen npm tokens.