On July 14th, an attacker hijacked AsyncAPI's own CI/CD pipeline to publish four trojanized npm packages under a trusted namespace – reaching 2.9 million weekly downloads before anyone noticed. No bad reputation, no known-malicious version, nothing for conventional defenses to catch. Here's how it happened, and what would have stopped it…
On June 17, a typosquatted npm package and stolen contributor credentials gave attackers access to 144 Mastra packages with nearly a million weekly downloads. Here's how the attack unfolded, how the malware evaded detection, and how to protect your pipeline…