AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads

2026-07-15T14:51:48Zf4f4a3f66891143f1cef9df0d3aba32657beb3b311d5ce09270ae057b383dd7a
AI-malicous-codeCISACVE-2008-4128CiscoCrashStealer','gatekeeper-bypass'KEVMicrosoftPatch-TuesdayPowerShellRATSMA-1000SonicWallVPNactive-exploitationcrypto-theftcryptorinfo-stealermacOSmalwarenpmransomware-infrastructurereconnaissancesanctionssupply-chainzero-day

What happened

Multiple high-impact incidents reported: an AsyncAPI npm supply-chain compromise injected malware into four packages with ~2M weekly downloads (info-stealer, crypto-theft, RAT capabilities); SonicWall disclosed active exploitation of two zero-days in SMA 1000 appliances (including arbitrary command execution) and related flaws were added by CISA to its KEV catalog alongside Microsoft and Cisco issues; Microsoft’s July 2026 Patch Tuesday fixed a record 621 CVEs including exploited zero-days; U.S. Treasury sanctioned a VPN provider and cryptor seller linked to ransomware infrastructure; other in

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f4f4a3f66891143f1cef9df0d3aba32657beb3b311d5ce09270ae057b383dd7a
Enrichment time
2026-07-15T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.