← Back to feed
vendor
Microsoft Security Blog
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack ch...
Read the full story
Microsoft Security Blog →