Cloudsmith Blog

Featured
Supply chain security
5 min read

Inside the AsyncAPI npm supply chain attack

On July 14th, an attacker hijacked AsyncAPI's own CI/CD pipeline to publish four trojanized npm packages under a trusted namespace – reaching 2.9 million weekly downloads before anyone noticed. No bad reputation, no known-malicious version, nothing for conventional defenses to catch. Here's how it happened, and what would have stopped it…
Supply chain security
5 min read

Inside the Mastra npm supply chain attack

On June 17, a typosquatted npm package and stolen contributor credentials gave attackers access to 144 Mastra packages with nearly a million weekly downloads. Here's how the attack unfolded, how the malware evaded detection, and how to protect your pipeline…
Latest
Series
Keep up to date with our monthly newsletter

By submitting this form, you agree to our privacy policy