← Back to feed
vendor Microsoft Security Blog

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Microsoft Security Blog Microsoft

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack ch...

T1195
Read the full story Microsoft Security Blog →

Related Coverage

vendor PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core Wordfence Blog · Sep 22 vendor Unmasking EvilTokens: Getting to the root of device code phishing Microsoft Security Blog · Sep 22 vendor Inside a Malicious, Stealthy WordPress Must Use Plugin Wordfence Blog · Sep 22