AsyncAPI + Jscrambler NPM Package Compromises

A
Anonymous
about 2 months ago
72 views
24 nodes

The attackers exploited a GitHub Actions workflow vulnerability in AsyncAPI and used a leaked npm credential in Jscrambler to inject modular, developer-focused credential-harvesting trojans into the affected packages.

React Flow mini map
AsyncAPI + Jscrambler NPM Package Compromises - FlowViz Gallery