AsyncAPI community friends
Starter pack by Fran Méndez
Friends from the AsyncAPI community.
#AsyncAPI is an active hashtag on Bluesky. In the last 30 days, 10 people shared 11 posts with it — around 0 a day. The busiest day was Jul 16 with 3 posts.
AsyncAPI community friends
Starter pack by Fran Méndez
Friends from the AsyncAPI community.
buff.ly
GitHub - microcks/microcks-testcontainers-dotnet: .NET lib for Testcontainers that enables embedding Microcks into your unit tests with lightweight, throwaway instance thanks to containers.
.NET lib for Testcontainers that enables embedding Microcks into your unit tests with lightweight, throwaway instance thanks to containers. - microcks/microcks-testcontainers-dotnet
buff.ly
@microcks/spectral-ruleset
A set of rules for Spectral that allows linting OpenAPI and AsyncAPI spec for Microcks conventions. Latest version: 0.0.6, last published: 29 minutes ago. Start using @microcks/spectral-ruleset in…
buff.ly
Your 1st AsyncAPI on Kafka mock
Microcks is Open Source cloud-native tool for API Mocking and Testing
plugins.jetbrains.com
AsyncAPI - IntelliJ IDEs Plugin | Marketplace
AsyncAPI Plugin for IntelliJ-based IDEs 🚀 Enhance your AsyncAPI development workflow directly within IntelliJ IDEA, Android Studio, and other JetBrains IDEs 📄 What...
github.com
GitHub - asyncapi/jasyncapi: /jay-sync-api/ is a Java code-first tool for AsyncAPI specification
/jay-sync-api/ is a Java code-first tool for AsyncAPI specification - asyncapi/jasyncapi
mailchi.mp
API Summit? API Standards? Getting us all together
What connects us is a shared passion for open-source, community, and APIs. We work at the booth during events, cover for each other when someone needs a break, and offer support—even if our companies ...
www.bleepingcomputer.com
AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.
www.hendryadrian.com
AsyncAPI npm packages infected with credential-stealing malware
Five malicious AsyncAPI packages were published to npm in a supply-chain attack that used compromised GitHub Actions workflows to deliver a remote access trojan with data-stealing capabilities. The attack affected widely used @asyncapi packages, leveraged legitimate publishing pipelines and SLSA attestations, and targeted secrets, browser data, wallets, and CI/CD credentials. #AsyncAPI #GitHubActions #npm #Miasma
www.stepsecurity.io
Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories - StepSecurity
On July 14, 2026 at 07:10 UTC, three packages in the AsyncAPI generator monorepo (@asyncapi/[email protected], @asyncapi/[email protected], and @asyncapi/[email protected]) were published to npm carrying an obfuscated dropper that fires the moment the library is loaded, not on install. The packages were published through the project's own legitimate GitHub Actions release workflow and carry valid npm OIDC provenance attestations, because the attacker didn't steal an npm token: they gained push access to the repository's next branch and let the project's real CI/CD pipeline do the publishing for them.
securityaffairs.com
AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads
AsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities.
thehackernews.com
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised AsyncAPI npm packages load a multi-stage botnet from IPFS after attackers abuse GitHub Actions, despite valid provenance attestations
thehackernews.com
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/[email protected] @asyncapi/[email protected] @asyncapi/[email protected] @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) "The
www.hendryadrian.com
Compromised AsyncAPI packages on npm deliver malware
A commit to the asyncapi/generator GitHub repository injected obfuscated JavaScript into source files across multiple packages, and four malicious versions were then published to npm on 2026-07-14. The active incident affects high-download packages including @asyncapi/generator, @asyncapi/generator-components, @asyncapi/generator-helpers, and @asyncapi/specs, with no revert, deprecation, or maintainer advisory published yet. #asyncapi/generator #asyncapi/specs
www.hendryadrian.com
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
Socket’s Threat Research Team found four compromised AsyncAPI npm packages in the @asyncapi namespace that deliver a multi-stage loader leading to the Miasma payload from IPFS. The malicious releases were published through trusted publishing via GitHub Actions, but the poisoned source commit already contained the implant and the final framework includes persistence, REST C2, and multiple fallback channels. #AsyncAPI #Miasma #GitHubActions #IPFS
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.