@asyncapi/generator-components@0.7.1
Malicious code in @asyncapi/generator-components (npm)
Analysis
Trojanized clone of the @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/generator packages. All three were published within seconds of each other with identical injected obfuscated code appended to legitimate source files. The payload uses javascript-obfuscator to hide a detached child_process.spawn call that runs an encoded second-stage payload via Node.js -e with detached:true, stdio:'ignore', and windowsHide:true, then immediately unrefs the process. The legitimate utility functions are preserved above the injection, making the packages appear functional. The same gitHead commit hash appears across all three packages. The packages are: @asyncapi/generator-helpers@1.1.1 (injected in src/utils.js), @asyncapi/generator-components@0.7.1 (injected in lib/utils/ErrorHandling.js), and @asyncapi/generator@3.3.1 (injected in lib/templates/config/validator.js).
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 09:00 AM
- analyzed
- Jul 14, 2026, 09:05 AM
Related advisories
browse all confirmed advisories →Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.