
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
On July 14, Microsoft Threat Intelligence uncovered a coordinated supply-chain compromise of the @asyncapi organization on npm, with five package versions republished using the same malicious loader. Because @asyncapi/specs is a transitive dependency and the code runs at import time rather than through postinstall, affected developer machines, CI/CD pipelines, and production services are not protected by “npm install --ignore-scripts.”











































