AsyncAPI npm Packages Compromised via GitHub Actions, Delivering Remote Access Implant
Five AsyncAPI npm packages with nearly 3 million weekly downloads were compromised through a GitHub Actions supply chain attack, injecting a remote-access implant.