Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Reported 16 Jul 2026 by otx · Severity: medium
On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code