Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

2026-07-16T02:52:18Z68ad280dacb155378876c952b59594f0cd513ec209fc3101b2ed4b9194d1a9e4
AsyncAPICI/CDSBOMcredential-protectiondependency-securityimport-time-executionleast-privilegemalwarenpmnpm-package-tamperingpackage-signingsoftware-supply-chainsupply-chain-compromise

What happened

Microsoft analyzed a supply‑chain compromise in the AsyncAPI npm ecosystem where threat actors compromised packages and abused trusted CI/CD workflows to push malicious code that executes at import time. The attack chain used CI pipeline trust and repository/registry access to inject import‑time payloads into published packages, enabling widespread downstream execution when developers installed or imported the compromised packages. The blog breaks down the techniques, indicators, and recommended defenses — e.g., protect CI credentials and package accounts, enable strong auth and 2FA, review/ep

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
68ad280dacb155378876c952b59594f0cd513ec209fc3101b2ed4b9194d1a9e4
Enrichment time
2026-07-16T02:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery · Baitaphish