Compromised npm Packages Spread Multi-Stage Botnet via Trusted Namespace
Attackers injected malicious code into four legitimate @asyncapi npm packages, exploiting the inherent trust developers place in well-known open-source namespaces. When the infected packages were loaded by Node.js applications, the malware silently downloaded an encrypted payload from IPFS — a decentralized network that makes takedown efforts significantly harder. The malware then established multiple C2 channels, persisted on the host, stole credentials, and moved laterally, turning a single dependency into a full-blown botnet node. This attack highlights the critical risk of unverified third-party dependencies entering production environments unchecked. Without proactive software composition analysis, organizations may be unknowingly running adversary-controlled code across their entire Node.js ecosystem.
Tactical Insight
Immediate actions
- Audit all projects using @asyncapi packages and verify installed versions against known-good hashes from official release manifests.
- Remove or quarantine affected packages and scan all systems that loaded the compromised modules for signs of Miasma loader activity.
Long-term improvements
- Integrate Software Composition Analysis (SCA) tools (e.g., Snyk, Socket.dev) into CI/CD pipelines to flag unexpected code changes or new network behaviors in dependencies.
- Enforce a private npm registry or package proxy (e.g., Artifactory, Verdaccio) with an approval workflow so only vetted package versions enter production builds.
- Implement a Software Bill of Materials (SBOM) process so every deployed application has a complete, auditable inventory of its third-party dependencies.
Detection measures
- Monitor outbound DNS and HTTP traffic from build servers and application hosts for connections to IPFS gateways or unusual C2 infrastructure.
- Deploy runtime application monitoring to alert on unexpected child process spawning, credential file access, or lateral movement attempts originating from Node.js processes.