AsyncAPI + Jscrambler NPM Package Compromises

A
Anonymous
10 days ago
18 views
24 nodes

The attackers exploited a GitHub Actions workflow vulnerability in AsyncAPI and used a leaked npm credential in Jscrambler to inject modular, developer-focused credential-harvesting trojans into the affected packages.

React Flow mini map