AsyncAPI npm Packages Compromised by Credential-Stealing Malware
Five harmful versions of AsyncAPI packages were uploaded to the Node Package Manager (npm) as part of a supply-chain attack that introduced a remote access trojan capable of stealing information. The attacker took advantage of a poorly configured GitHub Actions workflow, releasing trojanized packages within the @asyncapi namespace, which collectively garnered over 2.25 million downloads…
