AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials

A dangerous supply chain attack struck the AsyncAPI project on the npm registry, putting developers and automated build systems at risk. Attackers republished five package versions in about ninety minutes on July 14, 2026. Each version carried the same hidden loader that runs as soon as the code is imported. The malware does not rely […]

This article has been indexed from Cyber Security News

Read the original article: