Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

How Unprotected Release Branches Let Attackers Compromise AsyncAPI

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Kiran Raj
Word Count
3,694
Company Posts That Month
47
Language
English
Hacker News Points
-
Post removed?
No
Summary

In July 2026, five official @asyncapi npm packages were compromised through a supply-chain attack, introducing obfuscated remote-code-execution loaders into the generator monorepo and spec-json-schemas repository. This was not due to a typo-squatting, rogue npm login, or maintainer account takeover, but rather an exploitation of unprotected auto-publish branches on GitHub where unsigned commits triggered trusted GitHub Actions OIDC publish pipelines. The attack involved a sophisticated three-stage process using a require-time loader, an IPFS downloader, and a bundled framework called Miasma, which contained modules for beaconing, persistence, and potentially credential harvesting and AI-tool poisoning, although the latter were not activated in this attack. The incident affected any developer or CI job using the infected package versions, with @asyncapi/specs being particularly risky due to its widespread use as a core dependency. Despite the valid SLSA provenance attestations proving the origin of the builds, they did not ensure safety, and the attack highlighted vulnerabilities in branch protection, the insufficiency of --ignore-scripts defenses, and the potential severity of require-time execution, underscoring the need for comprehensive security measures including branch protection and pre-publish malware scans.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 8 2,479 445 126 -1%
Observability 1 3,732 711 187 -12%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.