← Back to feed
vendor Microsoft Security Blog

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Microsoft Security Blog Microsoft

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack ch...

T1195
Read the full story Microsoft Security Blog →

Related Coverage

vendor The Cloudflare Blog – Brought to you by EmDash Cloudflare Blog · Aug 24 vendor Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) Rapid7 Blog · Aug 24 vendor Say it once: introducing Bot Preference Sync Cloudflare Blog · Aug 21