Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Reported 16 Jul 2026 by otx · Severity: medium

On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code