[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3d_8hkFmYt94MgzmIur-8gAE_IVDiesR_VAklY9C_bM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"cca4dac9-4ac6-44b9-a907-f3c9e0ae20f9","asyncapi-npm-supply-chain-attack-delivers-import-time-malware-via-ipfs","a1d14093-10f9-418e-93a7-254b0e5364b0","AsyncAPI npm Supply Chain Attack Delivers Import-Time Malware via IPFS","Threat actors gained access to the @asyncapi npm organization and silently republished five legitimate package versions embedded with a malicious loader, meaning any developer who installed or updated these packages automatically executed attacker-controlled code at module-load time. This attack is particularly dangerous because it bypasses common npm security mitigations such as integrity checks that only validate package structure rather than behavioral intent. The second-stage payload was fetched from IPFS, a decentralized protocol that is difficult to block or take down through conventional domain-based controls, enabling persistent command-and-control. This incident highlights how trusted open-source ecosystems can be weaponized against downstream consumers who implicitly trust published packages without deeper verification.","**Immediate actions:**\n- Audit all direct and transitive dependencies for the five compromised @asyncapi package versions and replace them with verified clean releases.\n- Lock dependency versions using lockfiles (package-lock.json or yarn.lock) and enable integrity hash verification via `npm ci` in CI\u002FCD pipelines.\n\n**Long-term improvements:**\n- Implement a private npm registry or proxy (e.g., Artifactory, Verdaccio) to vet and cache approved package versions before they reach developers.\n- Enforce mandatory multi-factor authentication and least-privilege access controls on all npm organization accounts to reduce the blast radius of credential compromise.\n- Adopt a software composition analysis (SCA) tool that performs behavioral and reputation analysis, not just CVE matching, on third-party packages.\n\n**Detection measures:**\n- Monitor outbound network traffic from build and runtime environments for connections to IPFS gateways and other non-standard decentralized protocols.\n- Implement runtime application self-protection (RASP) or eBPF-based monitoring to alert on unexpected process execution or network calls triggered at module-load time.\n- Establish alerting for sudden version republications or ownership changes on critical open-source dependencies used in your software bill of materials (SBOM).",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AU-12: Audit Record Generation","SLSA Supply Chain Framework: Build Integrity Level 3","OWASP A06:2021 – Vulnerable and Outdated Components","SSDF PW.4: Reuse Existing, Well-Secured Software","GDPR Article 32: Security of Processing (for organizations processing EU data via affected packages)","published","2026-07-16T04:20:20.625882+00:00","2026-07-16T04:20:20.514+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F07\u002F15\u002Funpacking-asyncapi-npm-supply-chain-compromise-import-time-payload-delivery\u002F","unpacking-the-asyncapi-npm-supply-chain-compromise-and-import-time-payload-deliv-f0dd97","Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]