
AsyncAPI npm Supply Chain Attack Deploys Miasma RAT via Compromised GitHub Actions
AsyncAPI’s npm ecosystem was hit by a supply chain attack that used compromised GitHub Actions workflows to distribute a Miasma-associated remote access trojan (RAT). The malicious releases appeared under the project’s legitimate npm namespace, potentially exposing developer devices, CI/CD runners, documentation systems, and automated build environments. AsyncAPI provides an open-source specification and tools for creating […]
The post AsyncAPI npm Supply Chain Attack Deploys Miasma RAT via Compromised GitHub Actions appeared first on Cyber Security News.