
AsyncAPI npm Supply Chain Attack Delivers Miasma RAT
Date Observed: July 14, 2026Ecosystem: npm (@asyncapi organization)Targets: Developers, CI/CD runners, and build systems consuming AsyncAPI packagesAttack Type: CI/CD compromise

Date Observed: July 14, 2026Ecosystem: npm (@asyncapi organization)Targets: Developers, CI/CD runners, and build systems consuming AsyncAPI packagesAttack Type: CI/CD compromise

Date Observed: June 24, 2026 (LeoPlatform wave); follow-on @immobiliarelabs wave June 26, 2026Ecosystem: npm (primary); propagation logic also targets PyPI,

Date Observed: June 17, 2026Ecosystem: npm (@mastra scope)Targets: Developer workstations and CI/CD runners installing @mastra/* packagesAttack Type: Account takeover +

Date Observed: June 1, 2026Ecosystem: npm @redhat-cloud-services Targets: CI/CD pipelines and developer workstations consuming @redhat-cloud-services packages Attack Type: CI/CD pipeline compromise; preinstall

Date Observed: May 19, 2026Ecosystem: PyPI (Python)Targets: CI/CD runners, cloud workloads, Kubernetes clusters, developer environments consuming durabletaskAttack Type: Supply chain

Date Observed: May 19, 2026Ecosystem: npm (Node.js)Targets: @antV data visualization packages, echarts-for-react, timeago.js, size-sensor, canvas-nest.js, CI/CD pipelines, developer workstations.Attack Type:

Date Observed: May 11, 2026Ecosystem: npm, PyPITargets: Developers using @tanstack/react-router and related packages; UiPath, Mistral AI, OpenSearch, and Guardrails AI

Date Observed: Late April 2026Ecosystem: RubyGems and Go ModulesTargets: Developers, CI runners, and GitHub Actions pipelinesAttack Type: Malicious package campaign,

Date Observed: April 29–30, 2026Ecosystem: npm, PyPI, Packagist (PHP)Targets: SAP enterprise developers, AI/ML engineers, DevOps and DevSecOps teams using Intercom

Date Observed: April 23, 2026 Ecosystem: npm (Node.js) Targets: Developer workstations, GitHub Actions CI/CD pipelines, cloud environments, AI coding tool
Be the first to know about our latest product updates and company news.
No spam. Just the good stuff! We also respect your privacy and keep your info safe.