---
type: "article"
title: "Security Incident Update on AsyncAPI NPM Packages"
newsletter: "AsyncAPI Initiative"
newsletter_handle: "asyncapi-initiative"
newsletter_url: "https://usecommune.com/n/asyncapi-initiative"
author: "Thulisile Sibanda (@thulieblack)"
published: "2025-11-27T06:00:00.000Z"
canonical_url: "https://usecommune.com/n/asyncapi-initiative/a/security-incident-update-on-asyncapi-npm-packages"
markdown_url: "https://usecommune.com/n/asyncapi-initiative/a/security-incident-update-on-asyncapi-npm-packages.md"
chat_url: "https://usecommune.com/n/asyncapi-initiative/a/security-incident-update-on-asyncapi-npm-packages/chat"
source_url: "http://eepurl.com/js47Bs"
body_source: "imported"
likes: 0
replies: 0
body_words: 182
---

# Security Incident Update on AsyncAPI NPM Packages

[![](https://mcusercontent.com/3cdae6aed726d2e7490aec739/images/a402998d-3c23-fb75-796f-76cf09204187.png)](https://www.asyncapi.com/?utm_source=newsletter&utm_medium=email&utm_campaign=community_updates&utm_id=newsletter)

### **Security Update: AsyncAPI NPM Packages**

Hey, 👋🏿 AsyncAPI community!

Early this week, several AsyncAPI NPM packages were compromised after an attacker injected a worm into specific versions. Thanks to quick action from the community members, the issue was contained and resolved.

- [**Charlie Eriksen**](https://www.linkedin.com/in/charlie-eriksen-a318578) first identified and reported the compromised packages.
- [**Łukasz Górnicki**](https://www.linkedin.com/in/lukasz-gornicki-a621914) led the effort to deprecate affected versions and worked through challenges with the NPM review process.
- [**Ashish Padhy**](https://www.linkedin.com/in/ashish-padhy3023)supported the investigation into a GitHub Actions workflow vulnerability that likely enabled the credential theft.
- [**Fran Méndez**](https://www.linkedin.com/in/fmvilas) ensured all organizational secrets were rotated to secure our ecosystem moving forward.

We’re grateful to each of them for their fast, transparent, and collaborative response.

![](https://mcusercontent.com/3cdae6aed726d2e7490aec739/images/54948627-9c82-b0c8-c67e-8d792000af18.png)

Read the full incident details update written by [Ashish Padhy](https://www.linkedin.com/in/ashish-padhy3023) and [Florence Njeri](https://www.linkedin.com/in/florencenjeri).

[Read the blog post](https://www.asyncapi.com/blog/shai-hulud-postmortem "Read the blog post")

### 🤔Suggestions or Questions?

If you have any further questions, have a suggestion, or would like to join in the efforts and assistance, please write to us at**[security@asyncapi.com](mailto:security@asyncapi.com).**

[![GitHub](https://cdn-images.mailchimp.com/icons/social-block-v2/color-github-96.png)](https://github.comasyncapi)

[![LinkedIn](https://cdn-images.mailchimp.com/icons/social-block-v2/color-linkedin-96.png)](http://www.linkedin.com/company/asyncapi)

[![YouTube](https://cdn-images.mailchimp.com/icons/social-block-v2/color-youtube-96.png)](https://youtube.com/asyncapi)

[![Email](https://cdn-images.mailchimp.com/icons/social-block-v2/color-forwardtofriend-96.png)](mailto:info@asyncapi.io)

[![Website](https://cdn-images.mailchimp.com/icons/social-block-v2/color-link-96.png)](https://www.asyncapi.com/)

[![Spotify](https://cdn-images.mailchimp.com/icons/social-block-v2/color-spotify-96.png)](https://open.spotify.com/show/73BrcNwJ5ZI9ygR8nfElZi)

[![](https://mcusercontent.com/3cdae6aed726d2e7490aec739/images/ff9bc14e-c38f-d7f3-6861-b0d2af80d00c.png)](https://www.asyncapi.com/?utm_source=newsletter&utm_medium=email&utm_campaign=community_updates&utm_id=newsletter)

*Copyright © 2025 AsyncAPI Initiative, All rights reserved.*

***

## Discussion

No replies yet.
