Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended ...
Record details
Published: 15 July 2026
Source: Microsoft Responsible AI
Category: Field notes
Topics: Military & security
Retrieved: 17 July 2026
Related evidence
These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.
The UK's Defence Investment Plan Has a Lethal Drone Swarm Vision
Royal United Services Institute · 15 July 2026
FAQ: Voting System Vulnerabilities and How They Can Be Weaponized
Center for Democracy & Technology · 16 July 2026
Event Recap April 20, 2026 Empowering Communities to Navigate the AI-Cyber Frontier
UC Berkeley CLTC · 15 July 2026
News May 14, 2026 Cyber Resilience Corps Listed as Key Resource in CISA’s “CI Fortify” Initiative
UC Berkeley CLTC · 15 July 2026
News May 27, 2026 Event Recap: Washington Nonprofit Cyber Forum
UC Berkeley CLTC · 15 July 2026
News June 9, 2026 Op-Ed Calls for “Project Kaleidoscope” to Bolster Community Cyber Defense in the Age of AI
UC Berkeley CLTC · 15 July 2026
How to cite this record
ethics.ai (15 July 2026), “Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery,” evidence record 11318, https://ethics.ai/record/11318 (originally published by Microsoft Responsible AI).
Use and limitations
This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.