LWA-2026-6767 MAL-2025-190656 ↗ confirmed malware

@asyncapi/generator-components@0.7.1

Malicious code in @asyncapi/generator-components (npm)

Analysis

Trojanized clone of the @asyncapi/generator-helpers, @asyncapi/generator-components, and @asyncapi/generator packages. All three were published within seconds of each other with identical injected obfuscated code appended to legitimate source files. The payload uses javascript-obfuscator to hide a detached child_process.spawn call that runs an encoded second-stage payload via Node.js -e with detached:true, stdio:'ignore', and windowsHide:true, then immediately unrefs the process. The legitimate utility functions are preserved above the injection, making the packages appear functional. The same gitHead commit hash appears across all three packages. The packages are: @asyncapi/generator-helpers@1.1.1 (injected in src/utils.js), @asyncapi/generator-components@0.7.1 (injected in lib/utils/ErrorHandling.js), and @asyncapi/generator@3.3.1 (injected in lib/templates/config/validator.js).

analyzed by
Leitwacht
first seen
Jul 14, 2026, 09:00 AM
analyzed
Jul 14, 2026, 09:05 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.