
AsyncAPI Supply-Chain Attack Targets Developer Tokens, Cloud Keys and CI/CD Secrets
The malicious versions were published on July 141414, 202620262026, within around 909090 minutes. A ffected packages include @asyncapi/specs versions 6.11.2-alpha.1 and 6.11.2, @asyncapi/[email protected], @asyncapi/[email protected], and @asyncapi/[email protected]. The incident is significant because @asyncapi/specs is a transitive dependency for many AsyncAPI tools. This means the malicious code could have reached developer systems, CI/CD runners, container builds, and […]
The post AsyncAPI Supply-Chain Attack Targets Developer Tokens, Cloud Keys and CI/CD Secrets appeared first on Cyber Security News.