security: Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Microsoft Security Blog
2026-07-16
Microsoft reports that attackers compromised AsyncAPI npm packages and used trusted CI/CD workflows to distribute malware via npm. The writeup details the attack chain, import-time payload delivery, and suggested defenses.