AsyncAPI npm Supply Chain Attack (Miasma RAT) — July 2026
Summary
On July 14, 2026, attackers exploited a misconfigured pull_request_target GitHub Actions workflow in the AsyncAPI repository to exfiltrate a privileged CI service-account token, then used it to publish five trojanized versions of four @asyncapi npm packages collectively downloaded approximately 2.9 million times per week. Each version contained the Miasma RAT, a 92,000-line modular malware framework that executes at module-load time rather than on install, harvesting browser credentials, SSH keys, cloud secrets, and cryptocurrency wallet data before establishing persistence via multiple C2 channels. All five malicious versions were unpublished from npm approximately four hours after publication, but any developer or CI runner that imported an affected package during the exposure window may have had credentials and wallet data exfiltrated.
Connected Entities
2 entities · 10 linked investigations- a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2→mentioned with→AsyncAPI npm Supply Chain Attack (Miasma RAT) — July 2026(50%)
Timeline(13 events)
2026-04-29
A contributor identified the pull_request_target misconfiguration in AsyncAPI's manual-netlify-preview.yml workflow and submitted a proof-of-concept demonstrating the vulnerability.
Wiz M-Red-Team research2026-05-17
A proposed fix for the pull_request_target misconfiguration was submitted but was not merged into the AsyncAPI repository, leaving the vulnerability open for 58 more days.
Wiz M-Red-Team research2026-07-14
Payload compiled at approximately 04:10 UTC, approximately three hours before injection into the repository.
SafeDep research2026-07-14
At 05:08 UTC, attacker opened pull request #2155 against asyncapi/generator with obfuscated JavaScript payload hidden after approximately 1,000 bytes of whitespace. The attacker also opened 36 additional decoy pull requests proposing a fake charity donation page as camouflage.
Wiz M-Red-Team research2026-07-14
At 05:16 UTC, the misconfigured manual-netlify-preview.yml workflow executed the attacker's code and exfiltrated the asyncapi-bot service account token to a Rentry pastebin dead-drop (slug: elzotebo).
Wiz M-Red-Team research2026-07-14
At 06:58 UTC, attacker pushed malicious commit 3eab3ec to the next branch of asyncapi/generator, injecting the Miasma dropper into package source files using three obfuscation techniques.
SafeDep research2026-07-14
Between 07:10 and 07:11 UTC, three malicious packages were published to npm via AsyncAPI's legitimate GitHub Actions release workflow with valid OIDC provenance attestations: @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, and @asyncapi/generator-components@0.7.1.
StepSecurity and Chainguard research2026-07-14
Between 07:51 and 08:28 UTC, attacker pushed 11 commits to the asyncapi/spec-json-schemas repository, compromising the specs package.
StepSecurity research2026-07-14
At 08:06 and 08:30 UTC, two additional malicious versions were published to npm: @asyncapi/specs@6.11.2-alpha.1 and @asyncapi/specs@6.11.2, each with valid OIDC provenance attestations.
Chainguard and SafeDep research2026-07-14
Between approximately 11:12 and 11:18 UTC, all five malicious package versions were unpublished from the npm registry, ending the active distribution window.
StepSecurity research2026-07-15
Microsoft Security published its analysis of the incident, with specific focus on the import-time payload delivery technique as a mechanism for evading install-hook-based detections.
Microsoft Security Blog2026-07-15
Palo Alto Networks Unit42 updated its npm threat landscape report to reference the AsyncAPI incident in the context of import-time payload delivery as an emerging technique.
Palo Alto Networks Unit422026-07-21
GBHackers, CyberSecurityNews, and Rescana published public reports summarizing the incident, including the 'M-RED-TEAM v6.4' self-identification and the broader campaign context.
GBHackers / CyberSecurityNewsDecision Log
- #1publish⛓ pending8/1/2026, 12:12:31 PMhash: F78UemPLKYRp51nimkFFciM7wLFQLFSk9GEdrrq6nSqm
12 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/1/2026, 12:12:22 PM
last updated: 8/1/2026, 6:52:21 PM
avoid.net — verified advice for a post-truth world