{
  "id": 10280,
  "url": "https://thenextweb.com/news/upwind-asyncapi-npm-supply-chain-attack",
  "title": "Upwind links compromise of multiple AsyncAPI npm packages to coordinated attack on software release process",
  "summary": "Developers often assume that packages published through official channels have passed through a secure release process. That assumption is fundamental to modern software development, where open source components are routinely integrated into applications through automated dependency management. A new investigation suggests that confidence can be challenged when attackers gain access to the systems responsible for publishing software. [&hellip;] This story continues at The Next Web",
  "authors": "Kolawole Samuel Adebayo",
  "category": "news",
  "topics": "finance-investment",
  "orgs": null,
  "regions": null,
  "published_at": "2026-07-14T17:22:18.000Z",
  "fetched_at": "2026-07-14T18:17:25.054Z",
  "source_slug": "x-the-next-web-ai",
  "source_name": "The Next Web AI",
  "source_homepage": "https://thenextweb.com/topic/artificial-intelligence",
  "ethics_ai_record_url": "https://ethics.ai/record/10280",
  "original_url": "https://thenextweb.com/news/upwind-asyncapi-npm-supply-chain-attack",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}