Bottom line: The npm packages @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, @asyncapi/generator@3.3.1, and @asyncapi/specs (v6.11.2, v6.11.2-alpha.1) distribute malicious botnet software.
Four npm packages in the @asyncapi namespace have been compromised and distribute a multi-stage botnet loader. The security research teams of OX Security, SafeDep, Socket, and StepSecurity have identified the infections.
The security research teams of OX Security, SafeDep, Socket, and StepSecurity have identified four packages in the @asyncapi namespace on npm as compromised. These distribute a multi-stage botnet loader that could potentially be executed on developer machines and production environments.
Affected packages are @asyncapi/generator-helpers version 1.1.1, @asyncapi/generator-components version 0.7.1, @asyncapi/generator version 3.3.1, and @asyncapi/specs versions 6.11.2 and 6.11.2-alpha.1. The compromise affects core tooling components of the AsyncAPI ecosystem, which is widely used for documentation and code generation for event-driven APIs.
For CTOs, this represents a critical supply chain risk: since these packages are included as development dependencies in build and generation processes, infected versions can be executed during the build and grant access to developer environments and potentially to sensitive artifacts. Immediate verification of dependency tree entries and an update to secure versions are required.
Source: thehackernews.com · Published 15 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.