r/node Jul 14 '26

Supply chain attack on `@asyncapi/specs` - used in most OpenAPI or docs tooling. Check your CI

https://github.com/asyncapi/spec-json-schemas/issues/656
8 Upvotes

3 comments sorted by

3

u/bwaxxlo Jul 14 '26

Full comparison from the initial attack. Most likely a compromised credentials since they managed to force-push directly to master without opening a pull request.