[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVKMFyM7DRTXU7EjP3Eo30xfJhtYVOlGD5YJpTB25juk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"59844dba-7a45-4841-92f5-c9d75a374fa9","misconfigured-cicd-workflow-enables-asyncapi-npm-supply-chain-attack","db632332-8fa6-4cc0-b21a-4c1f4e8c721e","Misconfigured CI\u002FCD Workflow Enables AsyncAPI npm Supply-Chain Attack","A misconfigured GitHub Actions workflow allowed an attacker to inject malware into five AsyncAPI npm packages, exposing over 2.25 million weekly downloads to a credential-stealing remote access trojan. The root failure was a poorly secured CI\u002FCD pipeline that lacked proper controls over who or what could trigger package publishing workflows. This matters because developers implicitly trust packages from well-known ecosystems, meaning a single compromised package can silently harvest credentials, tokens, and sensitive data across thousands of downstream environments. Supply-chain attacks of this nature are particularly dangerous because the malicious code inherits the trust and reach of the legitimate project it piggybacks on.","**Immediate actions:**\n- Audit all GitHub Actions workflow files for overly permissive triggers (e.g., `pull_request_target`, write permissions granted to forks) and restrict them immediately.\n- Review npm publish permissions and rotate any exposed tokens or credentials that may have been harvested by the malicious packages.\n- Pin all npm dependencies to specific, verified commit SHAs or package digests rather than mutable version tags.\n\n**Long-term improvements:**\n- Implement a mandatory code-signing and provenance attestation process for all published packages using tools like npm provenance or Sigstore.\n- Enforce least-privilege access on CI\u002FCD pipelines by scoping secrets and publish tokens to only the jobs and environments that strictly require them.\n- Establish a Software Composition Analysis (SCA) gate in the build pipeline to automatically detect newly introduced malicious or anomalous package behavior before deployment.\n\n**Detection measures:**\n- Enable real-time monitoring and alerting on outbound network connections originating from CI\u002FCD runners to detect unexpected data exfiltration channels.\n- Subscribe to package security advisories (e.g., via GitHub Advisory Database, Socket.dev, or Snyk) to receive immediate notification when dependencies are flagged as malicious.\n- Regularly audit dependency trees and compare published package contents against source repository commits to identify unauthorized code injections.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 16: Application Software Security","NIST SP 800-161: Cybersecurity Supply Chain Risk Management","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 CM-3: Configuration Change Control","NIST SP 800-53 AC-6: Least Privilege","NIST SSDF PW.4: Reuse Existing, Well-Secured Software","SLSA Supply Chain Levels for Software Artifacts (Level 2+)","GDPR Article 32: Security of Processing (for EU orgs handling harvested personal data)","published","2026-07-15T16:20:24.882043+00:00","2026-07-15T16:20:24.536+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002F-asyncapi-npm-packages-infected-with-credential-stealing-malware\u002F","asyncapi-npm-packages-infected-with-credential-stealing-malware-2765d5","​    ​AsyncAPI npm packages infected with credential-stealing malware",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"cc175ece-0131-415a-9e3e-f3be15ccd794","2026-07-16","morning","ThreatNoir Morning Brief — July 16","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-16\u002Fthreatnoir-morning-brief-2026-07-16.mp3"]