Skip to content

164news.com

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Upwind links compromise of multiple AsyncAPI npm packages to coordinated attack on software release process

Posted on July 14, 2026 By 164news66 No Comments on Upwind links compromise of multiple AsyncAPI npm packages to coordinated attack on software release process

Upwind: AsyncAPI npm Packages Hit by Supply Chain Attack

Skip to content

Toggle Navigation

News

  • Events
    • TWN Conference
      • June 19 & 20, 2025
    • All events
  • Newsletters
  • Partner with us
  • Jobs
  • Contact

Latest

  • Deep tech
  • Sustainability
  • Ecosystems
  • Data and security
  • Fintech and ecommerce
  • Future of work
  • Conference media hub

More

  • Startups and technology
  • Investors and funding
  • Government and policy
  • Corporates and innovation
  • Podcast

Upwind Links Compromise of Multiple AsyncAPI NPM Packages to Coordinated Attack on Software Release Process

July 14, 2026 – 5:22 pm

Image by: Upwind

Developers often assume that packages published through official channels have passed through a secure release process. This assumption is fundamental to modern software development, where open source components are routinely integrated into applications through automated dependency management. A new investigation suggests that this confidence can be challenged when attackers gain access to the systems responsible for publishing software.

Cloud security company Upwind has released findings from an investigation into a coordinated attack affecting multiple official AsyncAPI npm packages. According to the company, the activity extended beyond a single compromised package and involved multiple repositories and publishing pipelines, allowing malicious code to be distributed through legitimate release channels.

The Investigation Uncovered Multiple Points of Compromise

Upwind’s research found that the campaign affected several parts of the AsyncAPI ecosystem:

  • GitHub Repositories: Attackers compromised two separate GitHub repositories.
  • Release Branches: They also observed attacks against different release branches.
  • OpenID Connect (OIDC) Publishing Identities: Abuse of different OIDC publishing identities within a relatively short timeframe.

These findings suggest the attackers gained access to multiple publishing pipelines rather than exploiting a single weakness in the release process.

The Investigation Concludes

The investigation concludes that the operation represented a coordinated campaign aimed at the software release process itself instead of a one-off package compromise.

Malicious Code Execution

One aspect of the campaign that drew researchers’ attention was how the malicious code was executed after the compromised packages were used:

  • Normal Package Imports: The attackers moved away from techniques commonly associated with npm supply chain attacks. Instead of using preinstall or postinstall scripts, the malicious code executed during normal package imports.
  • Alternative Execution Paths: It also executed through alternative execution paths. Because these actions occurred as part of expected application behavior, the activity would be more difficult to identify using security tools that focus primarily on monitoring package installation.

Researchers observed that while execution methods varied across the campaign, attackers reused the same infrastructure and malware patterns across the compromised repositories and publishing pipelines.

Implications Extend Beyond Package Maintainers

The affected packages were published through official channels and appeared legitimate to organizations relying on standard dependency management practices. That means the impact was not limited to the repositories themselves. Upwind stated that developer workstations and CI/CD environments that imported the affected packages should be treated as potentially compromised because the malicious code was designed to execute during routine package usage.

"This wasn’t just a malicious package – it was a compromise of trust," said Amiram Shachar, CEO at Upwind.

Clock

Post navigation

Previous Post: IBM shares plunge after preliminary Q2 revenue falls short of estimates despite surging AI bookings
Next Post: Affiliate Marketing SEO Hub: Mastering On-Page Optimization for Success

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Editor's Picks

  • brooklyn-real-estate-legal-services
  • New York Bankruptcy Expert
  • NYC Employment Law Firm
  • Long Island Business Litigation Lawyer
  • Bronx DWI Defense Attorney
  • Brooklyn Small Business Legal Advice
  • New York Personal Injury Attorney
  • NYC Construction Law Specialist
  • NY Criminal Defense Lawyer
  • Manhattan Family Law Specialist

Recent Posts

  • OpenAI wants its legal fees from xAI, while Apple comes for OpenAI
  • Huawei Digital Power now rivals Tesla’s energy division in revenue
  • Affiliate Site Security: Protecting Your Business and Users with Comprehensive Measures
  • Affiliate Marketing SEO Hub: Unlocking Success Through On-Page Optimization
  • Organic Traffic Generation: Boost Affiliate Marketing with Proven Strategies

Recent Comments

  1. fk777 casino on Spiro takes $55M from China’s NewTrails as it nears a $1bn valuation
  2. 5577betapp on Spiro takes $55M from China’s NewTrails as it nears a $1bn valuation
  3. 144bet1 on Spiro takes $55M from China’s NewTrails as it nears a $1bn valuation
  4. 144bet1 on Spiro takes $55M from China’s NewTrails as it nears a $1bn valuation
  5. 144bet1 on Spiro takes $55M from China’s NewTrails as it nears a $1bn valuation

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026

Editor's Picks

  • brooklyn-real-estate-legal-services
  • New York Bankruptcy Expert
  • NYC Employment Law Firm
  • Long Island Business Litigation Lawyer
  • Bronx DWI Defense Attorney
  • Brooklyn Small Business Legal Advice
  • New York Personal Injury Attorney
  • NYC Construction Law Specialist
  • NY Criminal Defense Lawyer
  • Manhattan Family Law Specialist

Copyright © 2026 164news.com.

Powered by PressBook Dark WordPress theme