Compromised npm Packages Spread Multi-Stage Botnet Malware
Attackers compromised several AsyncAPI npm packages to deliver multi-stage botnet malware. Developers who installed these packages unknowingly integrated malicious code into their systems. This incident highlights ongoing supply chain risks in open-source ecosystems.