← Back

Wire · operational-macro

AsyncAPI npm organization compromised, 2M weekly downloads affected

Published

14 July 2026

Topic

operational-macro

Sectors

Developer ToolsCybersecurity

Source

Read at ox.security

Verified

Fusion42 · 15 July 2026 · Fusion42 review

AsyncAPI's npm organisation was compromised, injecting a sophisticated multi-stage malware dropper into four core packages with 2M+ weekly downloads. The malware acts as a crypto-stealer, info-stealer and RAT, using IPFS and BitTorrent for persistence and attempting to self-replicate across npm, PyPI and Cargo registries.

This Wire brief sits within Fusion42's coverage of Developer Tools and Cybersecurity.

◆ The Wire takeaway

If you use AsyncAPI generator packages, your developer tokens and crypto wallets are now actively hunted. Revoke every npm, PyPI and Cargo token from any machine that downloaded versions 3.3.1 or earlier of @asyncapi/generator—the malware spreads itself across all three registries if it finds one working credential.

Coverage

1 source · 14 Jul 2026

Related on Wire

Topics

Developer ToolsCybersecuritynpm-securitysupply-chainmalwaredeveloper-toolspackage-compromise