NPM · JULY 2026 · EARLY WARNING

AsyncAPI npm Packages Reportedly Infected with Malware

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity: CRITICAL

An early warning has been issued regarding five malicious versions of AsyncAPI packages published to npm, which reportedly delivered a remote access trojan with info-stealing capabilities.

What happened

According to initial reports, an attacker compromised two AsyncAPI GitHub repositories and exploited a misconfigured GitHub Actions workflow to push trojanized packages. The affected versions are asyncapi 1.14.1 and 0.30.4, with a cumulative weekly download count of over 2.25 million. Security researchers have confirmed that the attack involved CI/CD pipeline compromises, not stolen npm tokens or malicious maintainers.

Professional software engineers using these packages should avoid the affected versions and monitor their environments for any suspicious activity. The incident is still under investigation, and further details may emerge as the situation develops. For the latest information, consult the primary sources provided.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If asyncapi is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats