Skip to content

AsyncAPI npm Packages Infected with Credential-Stealing Malware

To the point: Five AsyncAPI npm packages were infected with malware that steals credentials and enables remote access.

Five manipulated versions of AsyncAPI packages were uploaded to the npm repository and distributed a remote-access trojan with information-stealing functionality. This is a software supply-chain attack with significant security implications for developers and organizations.

Five malicious versions of AsyncAPI packages were injected into the Node Package Manager (npm) repository in a targeted supply-chain attack. The compromised versions distributed a remote-access trojan that can simultaneously steal information from the system.

For CISOs, this represents a critical risk in the dependency chain: developers who installed these packages may have unwittingly introduced malware into their environments. The trojan not only enables remote access to infected systems, but also espionage of login credentials and sensitive information.

Measures should urgently include verification of npm dependencies in your own software inventory and search for the affected AsyncAPI versions, as well as forensic analysis of systems on which these were installed. The npm registry and security tools should be monitored for suspicious updates in the dependency chain.


Source: www.bleepingcomputer.com · Published 15 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: