Reviewed threat campaign
AsyncAPI Miasma loader compromise
Socket documented four compromised packages in the @asyncapi npm namespace that delivered a multi-stage loader on macOS, Linux, and Windows through malicious published package contents.
Uncertainty
The record reflects Socket analysis published July 14, 2026. HOL has not independently attributed the actor or measured the full installed victim population.
Limitations
- Public campaign details intentionally omit live infrastructure and executable payload material.
Timeline
- · AsyncAPI Miasma loader compromise was first observed in the reviewed source material.
- · The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 635.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Guard coverage and non-coverage
- partial: coverage:stable:codex — Guard can apply package-install policy on eligible observed actions, but it does not replace registry intelligence or endpoint response after a malicious package has executed.
Defensive policy guidance
- Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Status: available. Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
Sources
- Socket: AsyncAPI namespace supply-chain attack · observed 2026-08-09