Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages
2026-07-14T20:51:39Z•096651705c13fc77fed7efab78be77af022bc9de7cdab2920616499e3d6156e2
asyncapiblackcatclaude-integrationcredentials-theftdestructive-malwaredeveloper-targetingdomain-serverholdgigawipermicrosoft-entranpmoauth-spoofingransomwaresiggenslacksteam-c2supply-chainsupply-chain-compromisetelegramvisual-studio
What happened
Multiple high-risk incidents reported: Upwind links a coordinated supply-chain campaign that compromised multiple AsyncAPI npm packages, impacting repositories, publishing pipelines and developer systems; Proofpoint describes large-scale OAuth client ID spoofing campaigns probing Microsoft Entra accounts to test credentials and evade sign-in detections; Dr.Web reports a Siggen Windows backdoor spreading via infected Visual Studio projects, using Steam for C2 and stealing credentials/crypto; Microsoft warns of GigaWiper, a destructive Windows backdoor capable of wiping disks, encrypting files,及
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 096651705c13fc77fed7efab78be77af022bc9de7cdab2920616499e3d6156e2
- Enrichment time
- 2026-07-14T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.