> AsyncAPI npm packages infected with credential-stealing malware
[AUTHOR: Bill Toulas]
[DATE: 15/07/2026 15:37]
[LANGUAGE: EN]
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. [...]