Compromised AsyncAPI npm packages: inside a CI supply-chain attack
Four @asyncapi npm packages (3M+ weekly downloads) were compromised to steal CI credentials — Datadog's detailed writeup offers actionable IOCs and a CI supply-chain attack playbook.
Summary written by editorial AI · Source link below
On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolded and how to know if you're affected.
Editorial Analysis
With millions of weekly downloads, this compromise could have silently harvested CI/CD secrets across a vast swathe of enterprises — exactly the systemic supply-chain risk the EU CRA aims to mitigate.
Audit your npm dependency trees for @asyncapi packages, rotate any CI/CD secrets on affected build servers, and enforce provenance checks.
A supply-chain attack on widely used npm packages compromised CI/CD credentials at scale — immediate audit and credential rotation are required.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Datadog Security Labs in a new tab.
More from the DevSecOps Desk
- CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages20 Jul
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts19 Jul
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT17 Jul
- VulnHunter: Capital One's agentic AI code security tool17 Jul
- The Prover Is the Judge: Verified Security Software from AI Coding Agents in Ada/SPARK17 Jul