Wire · technology
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 30 July 2026 · Fusion42 review
Attackers have compromised the popular '@asyncapi' npm organisation by abusing a misconfigured GitHub Actions workflow. This allowed them to publish malicious package versions with valid cryptographic provenance, meaning they appear as legitimate, signed releases.
This Wire brief sits within Fusion42's coverage of Developer Tools. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ ◆ The Wire takeaway
The signature that proves a package is legitimate has just been weaponised. Blind trust in supply chain provenance is over; you must now audit the GitHub workflow file that created the signature for every critical dependency.
◆ Related on Wire
◆ Topics