← Back to feed
Threat Actors & CampaignsEmerging1 sourceJul 14, 2026 · 00:00via Datadog Security Labs

Compromised AsyncAPI npm packages: inside a CI supply-chain attack

Brief

On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolded and how to know if you're affected.

Read more on Datadog Security Labs