Reviewed threat campaign

AsyncAPI Miasma loader compromise

Socket documented four compromised packages in the @asyncapi npm namespace that delivered a multi-stage loader on macOS, Linux, and Windows through malicious published package contents.

Severity highConfidence highReviewed 2026-08-09Expires 2026-09-08

Uncertainty

The record reflects Socket analysis published July 14, 2026. HOL has not independently attributed the actor or measured the full installed victim population.

Limitations

Timeline

  1. · AsyncAPI Miasma loader compromise was first observed in the reviewed source material.
  2. · The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 635.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Guard coverage and non-coverage

Defensive policy guidance

Sources