🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)

🔧 Programmierung 🕛 kürzlich 5 Min Lesezeit
0

AsyncAPI Supply Chain Attack Delivers Miasma RAT via NPM

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht

Originally published on open-source project, resulting in the publication of malicious versions of several popular repositories to inject a multi-stage malware loader that deploys the Miasma RAT. The attack is notable for its method: by committing malicious code to a development branch, the attackers abused the project's legitimate CI/CD workflow, powered by ): The attacker leveraged the trusted, automated CI/CD pipeline as a distribution mechanism. This is a form of Living-off-the-Land, but within the development infrastructure.

  • Payload Delivery: The malicious code was embedded within the packages and designed to activate post-installation, evading static analysis tools that only scan during install.

  • Malware: The final payload, Miasma RAT, is a potent botnet framework. Its cross-platform nature (Windows, macOS, Linux) is particularly dangerous in developer environments, which are often heterogeneous. It enables attackers to achieve persistence, exfiltrate sensitive data (such as API keys, credentials, and proprietary code), and move laterally within a network.




  • This attack highlights a critical flaw in relying solely on publisher identity verification, like OIDC provenance. While provenance proves who published a package, it cannot prove the integrity of the code within it. If the publisher's build process is compromised, it will simply sign and attest to malicious code.







    Impact Assessment



    The impact of this attack is significant and multi-faceted:





    • Developer Compromise: Any developer who downloaded and used the malicious package versions could have their machine compromised by the Miasma RAT.


    • Downstream Risk: Applications and services built using the compromised packages could be affected. The Miasma RAT could be active in production environments if the malicious packages were deployed.


    • Data Exfiltration: Compromised systems are at risk of having source code, environment variables, cloud credentials, and other sensitive developer secrets stolen.


    • Erosion of Trust: This attack undermines trust in the open-source ecosystem and the security of automated package management and CI/CD pipelines.






    IOCs — Directly from Articles

































    Type Value Description
    NPM Package @asyncapi/[email protected] Malicious version
    NPM Package @asyncapi/[email protected] Malicious version
    NPM Package @asyncapi/[email protected] Malicious version
    NPM Package @asyncapi/[email protected] Malicious version





    Cyber Observables — Hunting Hints



    Security teams may want to hunt for the following patterns to detect potential compromise:

































    Type Value Description
    File Name
    package-lock.json, yarn.lock
    Search for the specific malicious package versions listed in the IOCs.
    Network Traffic Pattern Outbound connections from build agents Monitor for unexpected network connections from CI/CD runners or developer machines to unknown IP addresses, especially shortly after a build process.
    Process Name node Look for node processes that spawn unexpected child processes or make unusual network connections, particularly in the context of a CI/CD job.
    Command-line Pattern
    npm install or npm ci
    While the payload doesn't run on install, logs of these commands can establish a timeline for when the malicious packages might have been introduced.





    Detection & Response




    1. Dependency Scanning: Immediately scan all projects for the presence of the malicious package versions. Tools like npm audit may help, but manual inspection of lock files is recommended.

    2. Log Review: Review CI/CD logs for build jobs that used the compromised packages. Analyze network logs from build runners for any anomalous outbound traffic.

    3. Endpoint Analysis: On developer machines, use EDR to hunt for persistence mechanisms, unusual network connections from node processes, or the presence of the Miasma RAT.

    4. Credential Rotation: If a compromise is suspected or confirmed, assume all secrets, API keys, and credentials on affected developer machines and CI/CD environments have been stolen. Initiate a full credential rotation.






    Mitigation




    1. Secure CI/CD Pipelines: Implement the principle of least privilege for CI/CD jobs. Restrict network access for build runners and ensure they cannot access sensitive production environments. This aligns with D3FEND's for all developers. Protect critical branches (e.g., main, release) with branch protection rules, requiring signed commits and multiple reviewers.

    2. Dependency Pinning: Use lock files (package-lock.json, yarn.lock) to ensure that builds are reproducible and use specific, vetted package versions. This is a form of .

    Vollständiger Original-Bericht
    Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
    ↗ Original-Artikel auf dev.to lesen
    Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    Teilen mit Netzwerk & Team:

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 0%
    🟡 In Evaluierung 0%
    🟢 Keine Auswirkung 0%
    Spannende Innovation 0%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    1 Quelle
    Hackers Just Poisoned the Rust Supply Chain | Threat Wire
    1 Quelle
    Hackers Found a Way Into Humanoid Robots | Threat Wire
    1 Quelle
    Bits und so #1021 (Passwort für Laufwerk)
    Ähnliche Beiträge
    🔍 Verwandte News

    Auch interessante Nachrichten AsyncAPI Supply Chain Attack Delivers Miasma RAT via NPM

    Thematisch verwandte Begriffe: AsyncAPI, Supply, Chain, Attack · 6 Treffer

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...