Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Adopt This Data Center Plushie and Hear Its Piercing Scream

    September 19, 2026

    If the AI Industry Followed Its Own Research, It Might Have Paused Already

    September 19, 2026

    Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Adopt This Data Center Plushie and Hear Its Piercing Scream
    • If the AI Industry Followed Its Own Research, It Might Have Paused Already
    • Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute
    • Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery
    • Here’s How an AI Slowdown Could Actually Be Enforced
    • Could AI really kill us all? Your questions, answered.
    • Turning Tech Talent Into Leadership Legacy
    • AI PACs Have Dumped Nearly $1 Million Into an Obscure Senate Race
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»AsyncAPI npm packages infected with credential-stealing malware
    Cybersecurity

    AsyncAPI npm packages infected with credential-stealing malware

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 15, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    AsyncAPI npm packages infected with credential-stealing malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.

    The threat actor exploited a misconfigured GitHub Actions workflow and pushed trojanized packages in the @asyncapi namespace that had a cummulative weekly download count of more than 2.25 million.

    Multiple security companies confirmed that on July 14, an attacker compromised two AsyncAPI GitHub repositories and injected malware into project files.

    “Both attacks are CI/CD pipeline compromises, not stolen npm tokens or malicious maintainers,” reads a report from Step Security.

    The researchers explain that “the attacker pushed commits under a placeholder git identity and let each repository’s real release workflow do the publishing via npm’s GitHub OIDC trusted-publisher integration.”

    In doing so, the attacker ensured that the resulting packages had the legitimate SLSA provenance attestations, indicating that they originated from an authorized workflow.

    The malicious AsyncAPI packages pushed to npm are:

    Application security company Socket notes that the first-stage implant in the published packages is an obfuscated JavaScript statement that ultimately triggers a downloader when the infected file is imported.

    A second-stage script, which contains configuration details and the main runtime, is retrieved from the IPFS peer-to-peer content delivery network and launched as a hidden process.

    Cloud and application security company Wiz says that the third-stage payload “is a 92,000-line malware framework with modular architecture,” which establishes persistence on the system and communicates with the command-and-control (C2) server over several channels: HTTP, Nostr relays, Ethereum smart contracts, and a libp2p mesh network.

    Attack flow diagram
    Source: Step Security

    Although the final payload uses artifact names and configuration files pointing to the Miasma backdoor seen in past supply-chain attacks [1, 2], SafeDep researchers believe that the malware is “either a private, parallel build by the same operators or a separate group that adopted the Miasma brand after the source was published.”

    Its purpose appears to be stealing secrets, which include credentials, authentication keys, tokens, browser data, sensitive info from CI/CD systems and AI developer tools, cryptocurrency wallets, and databases.

    Additionally, the malware code allows it to download the Gitleaks and HackBrowserData tools to help with collecting sensitive info.

    However, a report from cybersecurity company Aikido notes that all these functions do not work and the data harvesting tool exits before collecting anything. Nevertheless, the researchers say that all this can be achieved manually using the shell.

    Ox Security also noted that the malware performs a local check for Russia, and if there’s a match, it terminates its process.

    As of writing, all five versions of the four malicious packages have been removed from npm, but developers should note that existing installations and lock files created during the exposure window may still contain the malicious releases.

    The exposure window extends to approximately four hours and seven minutes, between 07:10 and 11:18 UTC on July 14.

    The recommended action is to pin to known-good files, regenerate lock files, remove the hidden ‘NodeJS/sync.js’ payload, terminate all malicious processes, and rotate credentials on the impacted systems.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    AsyncAPI credentialstealing Infected malware npm packages
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Adopt This Data Center Plushie and Hear Its Piercing Scream
    • If the AI Industry Followed Its Own Research, It Might Have Paused Already
    • Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute
    • Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery
    • Here’s How an AI Slowdown Could Actually Be Enforced

    Adopt This Data Center Plushie and Hear Its Piercing Scream

    September 19, 2026

    If the AI Industry Followed Its Own Research, It Might Have Paused Already

    September 19, 2026

    Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute

    September 19, 2026

    Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery

    September 18, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.