AsyncAPI npm Packages Reportedly Infected with Malware
An early warning has been issued regarding five malicious versions of AsyncAPI packages published to npm, which reportedly delivered a remote access trojan with info-stealing capabilities.
What happened
According to initial reports, an attacker compromised two AsyncAPI GitHub repositories and exploited a misconfigured GitHub Actions workflow to push trojanized packages. The affected versions are asyncapi 1.14.1 and 0.30.4, with a cumulative weekly download count of over 2.25 million. Security researchers have confirmed that the attack involved CI/CD pipeline compromises, not stolen npm tokens or malicious maintainers.
Professional software engineers using these packages should avoid the affected versions and monitor their environments for any suspicious activity. The incident is still under investigation, and further details may emerge as the situation develops. For the latest information, consult the primary sources provided.
How 0Day mitigates this
asyncapi is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.