AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads
2026-07-15T14:51:48Z•f4f4a3f66891143f1cef9df0d3aba32657beb3b311d5ce09270ae057b383dd7a
AI-malicous-codeCISACVE-2008-4128CiscoCrashStealer','gatekeeper-bypass'KEVMicrosoftPatch-TuesdayPowerShellRATSMA-1000SonicWallVPNactive-exploitationcrypto-theftcryptorinfo-stealermacOSmalwarenpmransomware-infrastructurereconnaissancesanctionssupply-chainzero-day
What happened
Multiple high-impact incidents reported: an AsyncAPI npm supply-chain compromise injected malware into four packages with ~2M weekly downloads (info-stealer, crypto-theft, RAT capabilities); SonicWall disclosed active exploitation of two zero-days in SMA 1000 appliances (including arbitrary command execution) and related flaws were added by CISA to its KEV catalog alongside Microsoft and Cisco issues; Microsoft’s July 2026 Patch Tuesday fixed a record 621 CVEs including exploited zero-days; U.S. Treasury sanctioned a VPN provider and cryptor seller linked to ransomware infrastructure; other in
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f4f4a3f66891143f1cef9df0d3aba32657beb3b311d5ce09270ae057b383dd7a
- Enrichment time
- 2026-07-15T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.