How Unprotected Release Branches Let Attackers Compromise AsyncAPI
Blog post from Endor Labs
In July 2026, five official @asyncapi npm packages were compromised through a supply-chain attack, introducing obfuscated remote-code-execution loaders into the generator monorepo and spec-json-schemas repository. This was not due to a typo-squatting, rogue npm login, or maintainer account takeover, but rather an exploitation of unprotected auto-publish branches on GitHub where unsigned commits triggered trusted GitHub Actions OIDC publish pipelines. The attack involved a sophisticated three-stage process using a require-time loader, an IPFS downloader, and a bundled framework called Miasma, which contained modules for beaconing, persistence, and potentially credential harvesting and AI-tool poisoning, although the latter were not activated in this attack. The incident affected any developer or CI job using the infected package versions, with @asyncapi/specs being particularly risky due to its widespread use as a core dependency. Despite the valid SLSA provenance attestations proving the origin of the builds, they did not ensure safety, and the attack highlighted vulnerabilities in branch protection, the insufficiency of --ignore-scripts defenses, and the potential severity of require-time execution, underscoring the need for comprehensive security measures including branch protection and pre-publish malware scans.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 8 | 2,479 | 445 | 126 | -1% |
| Observability | 1 | 3,732 | 711 | 187 | -12% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.