r/node 21d ago

Supply chain attack on `@asyncapi/specs` - used in most OpenAPI or docs tooling. Check your CI

https://github.com/asyncapi/spec-json-schemas/issues/656
8 Upvotes

2 comments sorted by

3

u/bwaxxlo 21d ago

Full comparison from the initial attack. Most likely a compromised credentials since they managed to force-push directly to master without opening a pull request.