AsyncAPI npm org compromised - 4 packages / 5 versions ship Miasma botnet loader via GitHub Actions `pull_request_target` pwn request
On 2026-07-14 an attacker exploited a pull_request_target misconfiguration in asyncapi/generator to steal a highly-privileged GitHub PAT, then published five malicious @asyncapi/* releases through the project's own trusted GitHub Actions release pipeline - valid npm OIDC provenance and all. The payload fires on require(), spawns a detached Node process, fetches an 8.25 MB IPFS loader (Miasma), and installs a 3.09 MB implant with six independent C2 channels (HTTP, Nostr, IPFS, BitTorrent DHT, libp2p GossipSub, Ethereum smart contract). Combined weekly downloads: ~2.9M.
Versions named here: 3.3.1