AsyncAPI's npm Compromise Shows Provenance Cannot Vouch for a Poisoned Pipeline

A pull_request_target workflow that had been flagged in April let an attacker publish signed, trojanised packages in July.

3 min read ·

On 14 July an attacker published five malicious versions of four packages in the @asyncapi npm namespace: @asyncapi/generator 3.3.1, @asyncapi/generator-helpers 1.1.1, @asyncapi/generator-components 0.7.1, and @asyncapi/specs 6.11.2-alpha.1 and 6.11.2. The first three went live at 07:10 UTC and the two specs releases followed within roughly ninety minutes. BleepingComputer put the combined weekly download count at about 2.25 million, most of it from @asyncapi/specs, which sits underneath a lot of API tooling. StepSecurity, Socket, Wiz, SafeDep, Aikido and Ox all flagged the releases, and the exposure window was about four hours.

Four hours is short. What makes this incident worth studying is how the attacker got in, and the fact that every one of those releases came out of AsyncAPI's own release pipeline with valid provenance attached.

How the pipeline was turned

Responses (2)

Sign in to leave a response.

  • Fakhrul

    The cooldown point is the one we can act on today. We already pin, but we adopt new patch versions the same day Renovate opens the PR, which is exactly the wrong habit for a four-hour window like this.

  • Worth repeating that ignore-scripts did nothing here. A lot of hardening guides still treat it as the main control, and attackers have clearly read them too.

More from Hana Rahman

Recommended from Horizon