{"type":"bundle","id":"bundle--069ddfde-0914-54b7-a229-b612a076846f","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--229a6359-0c12-5bda-8d31-2e86af18c5ae","created":"2026-08-09T11:30:00.000Z","modified":"2026-08-09T11:20:00.000Z","name":"AsyncAPI Miasma loader compromise","description":"Socket documented four compromised packages in the @asyncapi npm namespace that delivered a multi-stage loader on macOS, Linux, and Windows through malicious published package contents.","aliases":["AsyncAPI namespace compromise"],"first_seen":"2026-07-14T00:00:00.000Z","last_seen":"2026-07-14T00:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"Socket: AsyncAPI namespace supply-chain attack","url":"https://socket.dev/blog/asyncapi-supply-chain-attack"}]}]}