MIT TRACE

MIT CTL Logo
Back to Main Dashboard

AsyncAPI npm supply-chain compromise distributes Miasma malware through official packages

Attackers compromised AsyncAPI release workflows and used the project's legitimate CI/CD infrastructure to publish malicious versions of four official npm packages on July 14, 2026. The poisoned packages included @asyncapi/generator, @asyncapi/generator-helpers, @asyncapi/generator-components and @asyncapi/specs. Malicious code executed when affected packages were imported and downloaded an encrypted second-stage Miasma payload capable of establishing persistent remote access. Because @asyncapi/specs is a transitive dependency used throughout the AsyncAPI ecosystem, compromised releases could execute within developer workstations, CI/CD pipelines, container builds and production services that resolved and imported the affected versions. The incident represents a direct compromise of a legitimate software supply chain rather than simple typosquatting or publication of an unrelated malicious package.

79

Estimated severity

79 / 100

94

Source reliability

94 / 100

Approximate Date

14/07/2026

Targeted Company

ASYNCAPI INITIATIVE

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

Spain

ESP

Target country

No information

Affected countries

Spain

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information TechnologyEngineering & Maintenance

Attack Profile

Attack types

Software supply chain compromiseExploitation of misconfigurationMalwareUnauthorized access

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.