Hey, 👋🏿 AsyncAPI community!
Early this week, several AsyncAPI NPM packages were compromised after an attacker injected a worm into specific versions. Thanks to quick action from the community members, the issue was contained and resolved.
- Charlie Eriksen first identified and reported the compromised packages.
- Łukasz Górnicki led the effort to deprecate affected versions and worked through challenges with the NPM review process.
- Ashish Padhy supported the investigation into a GitHub Actions workflow vulnerability that likely enabled the credential theft.
- Fran Méndez ensured all organizational secrets were rotated to secure our ecosystem moving forward.
We’re grateful to each of them for their fast, transparent, and collaborative response.
|