---
answer: direct
beat: dev-practices
source: 1 article · updated: July 14, 2026
---

How many npm packages were compromised, and how widely were they used?

Attackers published five trojanized versions across four @asyncapi packages — generator, generator-helpers, generator-components, and specs — between 07:10 and 08:30 UTC on July 14, 2026. Per Wiz, the four packages combined for over 3 million weekly downloads, making this a wide-blast-radius compromise of AsyncAPI's tooling.

Answered in

A Misconfigured GitHub Action Backdoored Packages With 3M Weekly Downloads

A pull_request_target flaw in AsyncAPI's CI let attackers steal a token and trojan 4 npm packages — 3M+ weekly downloads — with credential-stealing code.

Crashtech Editorial July 14, 2026 Development Best Practices

Read the full analysis

Other questions this article answers

More development best practices questions

Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the Development Best Practices beat.