Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader

Reported 14 Jul 2026 by otx · Severity: medium

Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that