
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma‑associated Node.js backdoor through trusted GitHub Actions–driven release workflows and exposing high‑value developer and CI/CD environments to remote access, credential theft, and further lateral movement. Malicious versions were shipped for @asyncapi/[email protected], @asyncapi/[email protected], @asyncapi/[email protected], and @asyncapi/[email protected] and 6.11.2-alpha.1, together accounting for […]
The post AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News P...