Two npm Packages Compromised via Stolen Credentials15. July 2026CybersecurityAttackers exploited a GitHub Actions vulnerability to steal developer tokens and poison ten npm packages with modular malware. Share on:
Four AsyncAPI Packages Compromised with Multi-Stage Botnet15. July 2026CybersecurityThe npm packages @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, @asyncapi/generator@3.3.1, and @asyncapi/specs (v6.11.2, v6.11.2-alpha.1) distribute malicious botnet software. Share on: