← Back to feed
vendor Microsoft Security Blog

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Microsoft Security Blog • • Microsoft

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack ch...

T1195
Read the full story Microsoft Security Blog →

Related Coverage

vendor Cybersecurity Imperatives Will Demand AI Math Wordfence Blog · Oct 8 vendor Post-quantum authentication: Why organizations should start testing certificate ecosystems now Microsoft Security Blog · Oct 8 vendor Bridging technical depth and usability: The story behind Radar’s redesign Cloudflare Blog · Oct 8