Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageDevSecOps Desk
DevSecOps

Compromised AsyncAPI npm packages: inside a CI supply-chain attack

Four @asyncapi npm packages (3M+ weekly downloads) were compromised to steal CI credentials — Datadog's detailed writeup offers actionable IOCs and a CI supply-chain attack playbook.

Summary written by editorial AI · Source link below

Filed by Datadog Security Labs1 min readRead at source ↗

On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolded and how to know if you're affected.

Editorial Analysis

Why it matters

With millions of weekly downloads, this compromise could have silently harvested CI/CD secrets across a vast swathe of enterprises — exactly the systemic supply-chain risk the EU CRA aims to mitigate.

What to do

Audit your npm dependency trees for @asyncapi packages, rotate any CI/CD secrets on affected build servers, and enforce provenance checks.

Board brief

A supply-chain attack on widely used npm packages compromised CI/CD credentials at scale — immediate audit and credential rotation are required.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Datadog Security Labs

External link — opens at Datadog Security Labs in a new tab.

§
Continue with

More from the DevSecOps Desk