Inside the AsyncAPI Supply Chain Compromise
In July 2026, Microsoft Threat Intelligence uncovered a supply chain attack targeting the official AsyncAPI NPM organization. Attackers published malicious versions of multiple packages under the trusted AsyncAPI namespace, exploiting developer dependencies to distribute malware. The compromised packages deployed a multi-stage Remote Access Trojan through obfuscated lifecycle hooks that executed during routine build workflows. Upon installation, the malware retrieved second-stage payloads from IPFS gateways, established persistence on infected systems, and initiated command-and-control communications with external infrastructure. The attack leveraged trusted build automation and dynamic package retrieval via npx to bypass traditional security controls, affecting developers executing version-pinned tasks in their CI/CD pipelines.
Indicators of Compromise
- ip: 85.137.53.71
- hash: bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4
- hash: b9993a8ad0518849416798cf29668256ccb96598fc4423501ccab5312812653a
- hash: 24b9ee242f21a73b55f7bb3297eafb33c60840907386b542ed79fc6b72365168
- hash: 22bf76fe317ea6769bd38619bd440e42d119bd6b
- hash: c8cb3f6d5b90c46686d2bf531dc1a5786e27edc5
- hash: d602f4eeb914cf32782799376a8c5953
- hash: 93d8cffab1171a115228808e526d9bd7fe935e4e
- hash: d8a6b102c1715bd80393ce510931b1f6
- hash: ea895416fe585a5c2a5dce207190ff1c
Inside the AsyncAPI Supply Chain Compromise
Description
In July 2026, Microsoft Threat Intelligence uncovered a supply chain attack targeting the official AsyncAPI NPM organization. Attackers published malicious versions of multiple packages under the trusted AsyncAPI namespace, exploiting developer dependencies to distribute malware. The compromised packages deployed a multi-stage Remote Access Trojan through obfuscated lifecycle hooks that executed during routine build workflows. Upon installation, the malware retrieved second-stage payloads from IPFS gateways, established persistence on infected systems, and initiated command-and-control communications with external infrastructure. The attack leveraged trusted build automation and dynamic package retrieval via npx to bypass traditional security controls, affecting developers executing version-pinned tasks in their CI/CD pipelines.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.cyberproof.com/blog/inside-the-asyncapi-supply-chain-compromise/"]
- Adversary
- null
- Pulse Id
- 6a90b738237841eddd8428c7
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip85.137.53.71 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashbfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4 | — | |
hashb9993a8ad0518849416798cf29668256ccb96598fc4423501ccab5312812653a | — | |
hash24b9ee242f21a73b55f7bb3297eafb33c60840907386b542ed79fc6b72365168 | — | |
hash22bf76fe317ea6769bd38619bd440e42d119bd6b | — | |
hashc8cb3f6d5b90c46686d2bf531dc1a5786e27edc5 | — | |
hashd602f4eeb914cf32782799376a8c5953 | — | |
hash93d8cffab1171a115228808e526d9bd7fe935e4e | — | |
hashd8a6b102c1715bd80393ce510931b1f6 | — | |
hashea895416fe585a5c2a5dce207190ff1c | — |
Threat ID: 6a914c4eacd9273b49a4e3d3
Added to database: 08/28/2026, 08:52:30 UTC
Last updated: 08/28/2026, 16:06:20 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.