Country visual unavailable
No information
Attackers compromised AsyncAPI release workflows and used the project's legitimate CI/CD infrastructure to publish malicious versions of four official npm packages on July 14, 2026. The poisoned packages included @asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components and @asyncapi/specs. Malicious code executed when affected packages were imported and downloaded an encrypted second-stage Miasma payload capable of establishing persistent remote access. Because @asyncapi/specs is a transitive dependency used throughout the AsyncAPI ecosystem, compromised releases could execute within developer workstations, CI/CD pipelines, container builds and production services that resolved and imported the affected versions. The incident represents a direct compromise of a legitimate software supply chain rather than simple typosquatting or publication of an unrelated malicious package.
Estimated severity
79 / 100
Source reliability
94 / 100
Approximate Date
14/07/2026
Targeted Company
ASYNCAPI INITIATIVE
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Country visual unavailable
No information
Spain
ESP
Target country
No information
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone