Compromised @asyncapi npm Packages Distribute Multi‑Stage Botnet Loader
Patch all @asyncapi packages to the latest safe releases immediately and audit your dependency tree for other compromised packages.
Patch all @asyncapi/[email protected], @asyncapi/[email protected], @asyncapi/[email protected], and @asyncapi/[email protected] (and alpha) to the latest non‑compromised releases and run a dependency audit.
Summary
Four npm packages in the @asyncapi namespace have been compromised and are now distributing a multi‑stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are @asyncapi/generator‑[email protected], @asyncapi/generator‑[email protected], @asyncapi/[email protected], and @asyncapi/[email protected] (including the alpha release). The malicious code injects a loader that can download additional payloads after the initial infection. Developers who rely on these packages risk having their projects infected with a botnet that can be remotely controlled. The discovery highlights the importance of regularly auditing npm dependencies for known vulnerabilities. It also underscores the need for a robust package integrity verification process. Immediate action is required to mitigate potential compromise across projects that depend on these packages.
Key changes
- @asyncapi/[email protected] compromised
- @asyncapi/[email protected] compromised
- @asyncapi/[email protected] compromised
- @asyncapi/[email protected] and @asyncapi/[email protected] compromised
- Compromised packages distribute a multi‑stage botnet loader
- Discovery by OX Security, SafeDep, Socket, StepSecurity
- Attackers can inject malicious code into projects that depend on these packages
- The botnet loader can download additional payloads after initial infection