Supply Chain Attack
Compromised @asyncapi npm Packages Deliver Multi-Stage Botnet Loader
Another JavaScript-ecosystem supply-chain compromise, confirmed by four vendors: four @asyncapi npm packages were observed distributing a multi-stage botnet loader, and all five malicious versions have since been pulled from npm — defender inventory work this week.