{"schemaVersion":"guard-threat-campaign/v1","id":"HGTC-2026-ASYNCAPI26","slug":"asyncapi-miasma-loader-compromise","title":"AsyncAPI Miasma loader compromise","aliases":["AsyncAPI namespace compromise"],"summary":"Socket documented four compromised packages in the @asyncapi npm namespace that delivered a multi-stage loader on macOS, Linux, and Windows through malicious published package contents.","status":"published","severity":"high","confidence":"high","uncertainty":"The record reflects Socket analysis published July 14, 2026. HOL has not independently attributed the actor or measured the full installed victim population.","firstObservedAt":"2026-07-14T00:00:00.000Z","lastObservedAt":"2026-07-14T00:00:00.000Z","publishedAt":"2026-08-09T11:30:00.000Z","reviewedAt":"2026-08-09T11:20:00.000Z","expiresAt":"2026-09-08T23:59:59.000Z","reviewer":"HOL Guard Research","sources":[{"id":"source:socket-asyncapi","label":"Socket: AsyncAPI namespace supply-chain attack","url":"https://socket.dev/blog/asyncapi-supply-chain-attack","sourceType":"other_primary","observedAt":"2026-08-09T11:20:00.000Z"}],"artifacts":[{"id":"artifact:asyncapi-packages","artifactClass":"package","ecosystem":"npm","name":"@asyncapi affected package releases","version":null,"defanged":true}],"indicators":[],"timeline":[{"id":"timeline:first-observed","occurredAt":"2026-07-14T00:00:00.000Z","eventType":"first_observed","summary":"AsyncAPI Miasma loader compromise was first observed in the reviewed source material.","sourceIds":["source:socket-asyncapi"]},{"id":"timeline:disclosure","occurredAt":"2026-07-14T00:00:00.000Z","eventType":"disclosure","summary":"The reviewed source published or updated its defensive analysis and remediation guidance.","sourceIds":["source:socket-asyncapi"]}],"coverage":[{"assertionId":"coverage:stable:codex","relationship":"partial","limitation":"Guard can apply package-install policy on eligible observed actions, but it does not replace registry intelligence or endpoint response after a malicious package has executed."}],"policies":[{"policyId":"policy:package-install-review","purpose":"Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.","status":"available","limitation":"Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted."}],"limitations":["Public campaign details intentionally omit live infrastructure and executable payload material."],"correctionHref":"/guard/security/campaigns/asyncapi-miasma-loader-compromise/corrections"}