Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
2026-07-16T02:52:18Z•68ad280dacb155378876c952b59594f0cd513ec209fc3101b2ed4b9194d1a9e4
AsyncAPICI/CDSBOMcredential-protectiondependency-securityimport-time-executionleast-privilegemalwarenpmnpm-package-tamperingpackage-signingsoftware-supply-chainsupply-chain-compromise
What happened
Microsoft analyzed a supply‑chain compromise in the AsyncAPI npm ecosystem where threat actors compromised packages and abused trusted CI/CD workflows to push malicious code that executes at import time. The attack chain used CI pipeline trust and repository/registry access to inject import‑time payloads into published packages, enabling widespread downstream execution when developers installed or imported the compromised packages. The blog breaks down the techniques, indicators, and recommended defenses — e.g., protect CI credentials and package accounts, enable strong auth and 2FA, review/ep
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 68ad280dacb155378876c952b59594f0cd513ec209fc3101b2ed4b9194d1a9e4
- Enrichment time
- 2026-07-16T02:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.