← volver al portal

Four Compromised AsyncAPI Packages Distribute Multilayered Botnet Malware

Security researchers have identified four compromised packages from the @asyncapi namespace in the npm repository that are spreading a multistage botnet…

IT and security teams must immediately audit their npm dependencies to determine if they use the compromised versions of the listed @asyncapi packages. Update to secure versions and perform forensic analysis on systems that have installed these dependencies to detect botnet activity. Consider implementing integrity verification and package restrictions in your dependency manager.