Wire · operational-macro
AsyncAPI npm organization compromised, 2M weekly downloads affected
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 15 July 2026 · Fusion42 review
AsyncAPI's npm organisation was compromised, injecting a sophisticated multi-stage malware dropper into four core packages with 2M+ weekly downloads. The malware acts as a crypto-stealer, info-stealer and RAT, using IPFS and BitTorrent for persistence and attempting to self-replicate across npm, PyPI and Cargo registries.
This Wire brief sits within Fusion42's coverage of Developer Tools and Cybersecurity.
◆ ◆ The Wire takeaway
If you use AsyncAPI generator packages, your developer tokens and crypto wallets are now actively hunted. Revoke every npm, PyPI and Cargo token from any machine that downloaded versions 3.3.1 or earlier of @asyncapi/generator—the malware spreads itself across all three registries if it finds one working credential.
◆ Coverage
1 source · 14 Jul 2026
◆ Related on Wire
◆ Topics