Attackers compromised multiple AsyncAPI npm packages in coordinated supply chain raid

Upwind's investigation reveals that threat actors exploited the npm release process itself rather than individual package vulnerabilities. They gained access to legitimate developer credentials and published malicious versions of widely-trusted AsyncAPI libraries that developers would naturally download without suspicion. The compromise targeted established projects with thousands of weekly downloads—core infrastructure that enterprise teams rely on, not marginal risk. Official package repositories lack sufficient verification mechanisms between credential compromise and code publication, making the npm release process an increasingly attractive target for attackers seeking scale.