// supply chain security

All signals tagged with this topic

Attackers compromised multiple AsyncAPI npm packages in coordinated supply chain raid

Upwind's investigation reveals that threat actors exploited the npm release process itself rather than individual package vulnerabilities. They gained access to legitimate developer credentials and published malicious versions of widely-trusted AsyncAPI libraries that developers would naturally download without suspicion. The compromise targeted established projects with thousands of weekly downloads—core infrastructure that enterprise teams rely on, not marginal risk. Official package repositories lack sufficient verification mechanisms between credential compromise and code publication, making the npm release process an increasingly attractive target for attackers seeking scale.

Supply chain attackers now targeting SAP and npm developer tools

Attackers are shifting from infrastructure to the tools developers use daily. Stealing credentials from SAP systems and npm packages penetrates deeper into enterprise operations than previous tactics. A compromised dependency can distribute malware across thousands of downstream projects at once, forcing organizations to treat their development toolchain as a security perimeter, not an engineering convenience. The targeting of both enterprise software and open-source package managers shows attackers are weaponizing the entire developer ecosystem simultaneously.