# Compromised AsyncAPI npm packages: inside a CI supply-chain attack

DevFeed: [Compromised AsyncAPI npm packages: inside a CI supply-chain attack](<https://devfeed.tech/articles/compromised-asyncapi-npm-packages-inside-a-ci-supply-chain-attack-8282.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/compromised-asyncapi-npm-packages/>)

Author: Christophe Tafani-Dereeper, Sebastian Obregoso, Eslam Salem

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [C2](<https://devfeed.tech/topics/c2.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [IPFS](<https://devfeed.tech/topics/ipfs.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Nostr](<https://devfeed.tech/topics/nostr.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [github](<https://devfeed.tech/tags/github.md>), [go](<https://devfeed.tech/tags/go.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

## AI overview

This security article examines a CI supply-chain attack in which four compromised @asyncapi npm packages distributed credential-stealing malware. It traces the injected GitHub code, its IPFS-hosted second stage, encrypted configuration, credential harvesting, persistence mechanisms, and resilient command-and-control channels.

## Source excerpt

On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolded and how to know if you're affected.