Security News AsyncAPI npm packages infected with credential-stealing malware BleepingComputer Daniel Bender 15 Jul 2026 Share Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.