Briefing

Compromised @asyncapi npm Packages Distribute Multi‑Stage Botnet Loader

security
by [email protected] (The Hacker News) ·

Patch all @asyncapi packages to the latest safe releases immediately and audit your dependency tree for other compromised packages.

What to do now

Patch all @asyncapi/[email protected], @asyncapi/[email protected], @asyncapi/[email protected], and @asyncapi/[email protected] (and alpha) to the latest non‑compromised releases and run a dependency audit.

Summary

Four npm packages in the @asyncapi namespace have been compromised and are now distributing a multi‑stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are @asyncapi/generator‑[email protected], @asyncapi/generator‑[email protected], @asyncapi/[email protected], and @asyncapi/[email protected] (including the alpha release). The malicious code injects a loader that can download additional payloads after the initial infection. Developers who rely on these packages risk having their projects infected with a botnet that can be remotely controlled. The discovery highlights the importance of regularly auditing npm dependencies for known vulnerabilities. It also underscores the need for a robust package integrity verification process. Immediate action is required to mitigate potential compromise across projects that depend on these packages.

Key changes

  • @asyncapi/[email protected] compromised
  • @asyncapi/[email protected] compromised
  • @asyncapi/[email protected] compromised
  • @asyncapi/[email protected] and @asyncapi/[email protected] compromised
  • Compromised packages distribute a multi‑stage botnet loader
  • Discovery by OX Security, SafeDep, Socket, StepSecurity
  • Attackers can inject malicious code into projects that depend on these packages
  • The botnet loader can download additional payloads after initial infection

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting