Vendor
critical
advisory
AsyncAPI npm Supply Chain Compromise via GitHub Actions
2 rules 9 TTPs 3 IOCsThreat actors compromised AsyncAPI npm packages by exploiting a misconfigured GitHub Actions workflow, stealing a privileged bot token, and injecting obfuscated Miasma malware into multiple packages, which then executed at module-load time to establish persistence and command and control, bypassing standard npm installation mitigations.
@asyncapi/generator@3.3.1 +4
supply-chain
npm
github-actions
malware
javascript
nodejs
ci-cd
2r
9t
3i
high
advisory
Shai-Hulud Campaign Activity
20 IOCsTracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.
jscrambler 8.14.0 +102
campaign
shai-hulud
20i
updated