Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages
Software supply chains have become an increasingly attractive target for attackers because a single compromise can ripple across countless development environments. Instead of breaking into individual organizations, threat actors are increasingly seeking access to the trusted infrastructure used to distribute software, allowing malicious code to spread through legitimate channels.
New research from Upwind offers another example of that shift. The cloud security company disclosed findings from an investigation into a coordinated attack that affected multiple official AsyncAPI npm packages, revealing compromises across repositories and publishing pipelines rather than a single isolated package.
SecurityProducts & Services
An attack that reached beyond one repository
Upwind’s investigation found that the campaign impacted multiple components of the AsyncAPI ecosystem.
Researchers confirmed that attackers compromised two separate GitHub repositories while also identifying a second independent repository compromise. According to the company, the attackers targeted different release branches and abused different OpenID Connect (OIDC) publishing identities...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE