@asyncapi/specs@6.11.2
Malicious code in @asyncapi/specs (npm)
Analysis
A trojanized version of the @asyncapi/specs package. On import, index.js downloads a payload from hxxps://ipfs[.]io/ipfs/Qmet4fhsAaWMBUxNDfREHwgiyDeSWy4YSYs9wiKUW5jGyf and saves it to a platform-specific path (~/.local/share/NodeJS/sync.js on Linux, %LOCALAPPDATA%/NodeJS/sync.js on Windows, ~/Library/Application Support/NodeJS/sync.js on macOS). It then spawns the downloaded file as a detached, hidden child process (stdin/stdout/stderr discarded, windows hidden) and exits. The legitimate schema-export code is preserved at the bottom of the file to appear benign.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 09:18 AM
- analyzed
- Jul 14, 2026, 09:18 AM
- weekly installs
- 2,741,713
Related advisories
- @asyncapi/generator@3.3.1
- @asyncapi/generator-components@0.7.1
- @asyncapi/generator-helpers@1.1.1
- express-ini@12.1.10
- mailconfirmer@3.3.21
- shadxino@1.0.7
- tailwindcss-effector@1.7.0
- yian666aikf@1.0.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.