Cloudsmith Blog

Supply chain security
Supply chain security
5 min read

Inside the AsyncAPI npm supply chain attack

On July 14th, an attacker hijacked AsyncAPI's own CI/CD pipeline to publish four trojanized npm packages under a trusted namespace – reaching 2.9 million weekly downloads before anyone noticed. No bad reputation, no known-malicious version, nothing for conventional defenses to catch. Here's how it happened, and what would have stopped it…
Supply chain security
5 min read

Inside the Mastra npm supply chain attack

On June 17, a typosquatted npm package and stolen contributor credentials gave attackers access to 144 Mastra packages with nearly a million weekly downloads. Here's how the attack unfolded, how the malware evaded detection, and how to protect your pipeline…
Showing 1 to 12 of 110 results
Keep up to date with our monthly newsletter

By submitting this form, you agree to our privacy policy