July 15, 2026

Upwind links compromise of multiple AsyncAPI npm packages to coordinated attack on software release process

A tree with money growing out of it
UNICEF / Unsplash

Developers often assume that packages published through official channels have passed through a secure release process. That assumption is fundamental to modern software development, where open source components are routinely integrated into applicat...