Cato CTRL Threat Brief: AsyncAPI Supply Chain Attack Delivers Miasma Malware Through Trusted npm Packages
On July 14, 2026, attackers compromised release processes connected to the AsyncAPI open- source project and published malicious versions of four widely used npm packages with a combined reach of approximately 2.9 million weekly downloads.