On July 14th, an attacker hijacked AsyncAPI's own CI/CD pipeline to publish four trojanized npm packages under a trusted namespace – reaching 2.9 million weekly downloads before anyone noticed. No bad reputation, no known-malicious version, nothing for conventional defenses to catch. Here's how it happened, and what would have stopped it…