← Back

Wire · technology

Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware

Published

29 July 2026

Topic

technology

Sectors

Developer Tools

Source

Read at gbhackers.com

Verified

Fusion42 · 30 July 2026 · Fusion42 review

Attackers have compromised the popular '@asyncapi' npm organisation by abusing a misconfigured GitHub Actions workflow. This allowed them to publish malicious package versions with valid cryptographic provenance, meaning they appear as legitimate, signed releases.

This Wire brief sits within Fusion42's coverage of Developer Tools. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

The signature that proves a package is legitimate has just been weaponised. Blind trust in supply chain provenance is over; you must now audit the GitHub workflow file that created the signature for every critical dependency.

Related on Wire

Topics

Developer Toolssupply-chain-attacknpmgithub-actionsmalwareprovenancecicd