← Back to Tech & Science

Malicious AsyncAPI Packages Target Developer Credentials in Supply Chain Attack

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

LONDON (July 15, 2026) — A threat actor exploited a misconfigured GitHub Actions workflow to publish five malicious versions of popular AsyncAPI packages on the npm registry, launching a supply-chain attack designed to steal credentials from developer environments. The compromised software was distributed through legitimate package channels, targeting continuous integration and deployment systems as well as individual developer tools.

The attack vector relied on unauthorized access to an automated build process. By manipulating the configuration of the GitHub Actions workflow, attackers were able to inject malicious code into the AsyncAPI packages before they were signed and published. Once installed by unsuspecting developers or integrated into corporate pipelines, the compromised versions executed payloads intended to exfiltrate sensitive authentication tokens, API keys, and other critical credentials.

Security researchers identified five distinct malicious releases on Tuesday afternoon. The packages appeared identical in function to their legitimate counterparts but contained hidden routines that searched for environment variables containing secrets commonly used in cloud infrastructure management. Upon detection of these values, the malware transmitted them to external command-and-control servers controlled by the threat actor.

The AsyncAPI specification is widely adopted globally for defining machine-to-machine communication interfaces, making its associated tools a high-value target for attackers seeking access to enterprise networks. The breach highlights vulnerabilities in open-source supply chains where automated workflows can be hijacked if not properly secured with strict permission controls and multi-factor authentication requirements.

Developers who have installed the affected versions of AsyncAPI packages are urged to immediately remove them from their systems and rotate any credentials that may have been exposed during the infection window. The npm registry has since removed the malicious files, but copies remain in local caches on infected machines unless explicitly purged by users or automated security tools.

The identity of the threat actor behind the intrusion remains unknown at this time. While no specific organization has claimed responsibility for the attack, the sophistication of the workflow manipulation suggests a targeted operation rather than opportunistic malware distribution. Investigators are examining whether other packages within the same repository ecosystem were similarly compromised before the breach was detected.

Questions remain regarding the full scope of data exfiltration and how long the misconfigured workflow remained active prior to discovery. Additionally, it is unclear if the attackers attempted to cover their tracks by modifying logs or deleting evidence from the GitHub Actions history. As developers scramble to patch affected systems, cybersecurity firms are monitoring for new variants of the malware that may emerge in response to containment efforts.

Discussion

0 / 2000