Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

2026-07-16T08:52:22Z46dd60ea5ca40f440f2036b606092a5f02305b0ba8ae5a6f40d69902e65c156c
AsyncAPIBLUERABBITCI/CDCSPMDefender ExpertsEntra IDGigaWiperOAuth abuseSBOMSFISaaS securitySecure Future InitiativeShinyHunterscloud securitydestructive malwareidentity securityimport-time payloadleast-privilegemalwarenpmpartner ecosystempasskeyssupply-chainthreat intelligencevishing

What happened

Feed of Microsoft Security Blog posts (July 2026) covering multiple high-risk topics: a supply‑chain compromise of AsyncAPI npm packages that abused trusted CI/CD workflows to deliver import‑time payloads; ShinyHunters‑style OAuth abuse targeting SaaS (vishing, supply‑chain vectors, misconfigured guest access); GigaWiper (aka BLUERABBIT), a destructive backdoor built from multiple malware families; Entra ID authentication changes (passkeys default) and other hardening guidance; and broader operational guidance (Defender Experts, Secure Future Initiative, CSPM insights, partner ecosystem harden

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
46dd60ea5ca40f440f2036b606092a5f02305b0ba8ae5a6f40d69902e65c156c
Enrichment time
2026-07-16T08:52:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.