Skip to main content
Sign in

AsyncAPI npm Supply Chain Attack (Miasma RAT) — July 2026

avoid.net/asyncapi-npm-supply-chain-attack-miasma-rat-july-20260/100·95% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

On July 14, 2026, attackers exploited a misconfigured pull_request_target GitHub Actions workflow in the AsyncAPI repository to exfiltrate a privileged CI service-account token, then used it to publish five trojanized versions of four @asyncapi npm packages collectively downloaded approximately 2.9 million times per week. Each version contained the Miasma RAT, a 92,000-line modular malware framework that executes at module-load time rather than on install, harvesting browser credentials, SSH keys, cloud secrets, and cryptocurrency wallet data before establishing persistence via multiple C2 channels. All five malicious versions were unpublished from npm approximately four hours after publication, but any developer or CI runner that imported an affected package during the exposure window may have had credentials and wallet data exfiltrated.

Connected Entities

2 entities · 10 linked investigations
Wallets
a7e18d…2bf2
Organizations
AsyncAPI npm Supply Chain Attack (Miasma RAT) — July 2026
Relationships
  • a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2mentioned withAsyncAPI npm Supply Chain Attack (Miasma RAT) — July 2026(50%)
Have evidence about AsyncAPI npm Supply Chain Attack (Miasma RAT) — July 2026?

Timeline(13 events)

2026-04-29

A contributor identified the pull_request_target misconfiguration in AsyncAPI's manual-netlify-preview.yml workflow and submitted a proof-of-concept demonstrating the vulnerability.

Wiz M-Red-Team research

2026-05-17

A proposed fix for the pull_request_target misconfiguration was submitted but was not merged into the AsyncAPI repository, leaving the vulnerability open for 58 more days.

Wiz M-Red-Team research

2026-07-14

Payload compiled at approximately 04:10 UTC, approximately three hours before injection into the repository.

SafeDep research

2026-07-14

At 05:08 UTC, attacker opened pull request #2155 against asyncapi/generator with obfuscated JavaScript payload hidden after approximately 1,000 bytes of whitespace. The attacker also opened 36 additional decoy pull requests proposing a fake charity donation page as camouflage.

Wiz M-Red-Team research

2026-07-14

At 05:16 UTC, the misconfigured manual-netlify-preview.yml workflow executed the attacker's code and exfiltrated the asyncapi-bot service account token to a Rentry pastebin dead-drop (slug: elzotebo).

Wiz M-Red-Team research

2026-07-14

At 06:58 UTC, attacker pushed malicious commit 3eab3ec to the next branch of asyncapi/generator, injecting the Miasma dropper into package source files using three obfuscation techniques.

SafeDep research

2026-07-14

Between 07:10 and 07:11 UTC, three malicious packages were published to npm via AsyncAPI's legitimate GitHub Actions release workflow with valid OIDC provenance attestations: @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, and @asyncapi/generator-components@0.7.1.

StepSecurity and Chainguard research

2026-07-14

Between 07:51 and 08:28 UTC, attacker pushed 11 commits to the asyncapi/spec-json-schemas repository, compromising the specs package.

StepSecurity research

2026-07-14

At 08:06 and 08:30 UTC, two additional malicious versions were published to npm: @asyncapi/specs@6.11.2-alpha.1 and @asyncapi/specs@6.11.2, each with valid OIDC provenance attestations.

Chainguard and SafeDep research

2026-07-14

Between approximately 11:12 and 11:18 UTC, all five malicious package versions were unpublished from the npm registry, ending the active distribution window.

StepSecurity research

2026-07-15

Microsoft Security published its analysis of the incident, with specific focus on the import-time payload delivery technique as a mechanism for evading install-hook-based detections.

Microsoft Security Blog

2026-07-15

Palo Alto Networks Unit42 updated its npm threat landscape report to reference the AsyncAPI incident in the context of import-time payload delivery as an emerging technique.

Palo Alto Networks Unit42

2026-07-21

GBHackers, CyberSecurityNews, and Rescana published public reports summarizing the incident, including the 'M-RED-TEAM v6.4' self-identification and the broader campaign context.

GBHackers / CyberSecurityNews
Provenance & Audit Trail
12 Wayback Archives

Decision Log

  • #1publish⛓ pending8/1/2026, 12:12:31 PM
    hash: F78UemPLKYRp51nimkFFciM7wLFQLFSk9GEdrrq6nSqm

12 of 12 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/1/2026, 12:12:22 PM

last updated: 8/1/2026, 6:52:21 PM

avoid.net — verified advice for a post-truth world