Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
2026-07-16T08:52:22Z•46dd60ea5ca40f440f2036b606092a5f02305b0ba8ae5a6f40d69902e65c156c
AsyncAPIBLUERABBITCI/CDCSPMDefender ExpertsEntra IDGigaWiperOAuth abuseSBOMSFISaaS securitySecure Future InitiativeShinyHunterscloud securitydestructive malwareidentity securityimport-time payloadleast-privilegemalwarenpmpartner ecosystempasskeyssupply-chainthreat intelligencevishing
What happened
Feed of Microsoft Security Blog posts (July 2026) covering multiple high-risk topics: a supply‑chain compromise of AsyncAPI npm packages that abused trusted CI/CD workflows to deliver import‑time payloads; ShinyHunters‑style OAuth abuse targeting SaaS (vishing, supply‑chain vectors, misconfigured guest access); GigaWiper (aka BLUERABBIT), a destructive backdoor built from multiple malware families; Entra ID authentication changes (passkeys default) and other hardening guidance; and broader operational guidance (Defender Experts, Secure Future Initiative, CSPM insights, partner ecosystem harden
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 46dd60ea5ca40f440f2036b606092a5f02305b0ba8ae5a6f40d69902e65c156c
- Enrichment time
- 2026-07-16T08:52:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.