Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Several npm packages from the @asyncapi namespace have been found to be distributing a sophisticated multi-stage botnet malware, posing a significant risk to developers and their systems. These compromised packages, including @asyncapi/generator-helpers and others, were identified by security firms OX Security, SafeDep, Socket, and StepSecurity. This incident highlights the vulnerability of popular package repositories and underscores the importance of vigilant monitoring and secure coding practices to mitigate risks from supply chain attacks. The discovery is a stark reminder of how even trusted platforms can be exploited for malicious purposes.
Original Source
Read the full article at Thehackernews →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.