##ASyncAPI
@kinlane.bsky.social published a sharp piece worth reading: if the model can generate the API, why do you still need the standards? He traces the same mistake from SOAP/WSDL. The deterministic artifacts (#OpenAPI, #Arazzo, #JSONSchema, #AsyncAPI) are what make a generated API something governable
September 25, 2026 at 10:49 AM
Many integration workflows are a mix of REST and event-driven working in concert. That's exactly why Arazzo 1.1 added AsyncAPI support.

Next week I'm joining the #AsyncAPI community to show how #Arazzo and AsyncAPI give agents a machine-readable map of those mixed workflows.

👉 luma.com/zhcf7zvq
Making AI Agents Reliable Event-Driven API Consumers with Arazzo · Luma
AI agents are increasingly expected to act across any of your APIs, publishing to a queue, waiting on a webhook, correlating an async response, not just…
luma.com
September 17, 2026 at 2:48 PM
📢 Compromission de la chaîne d'approvisionnement AsyncAPI via des packages NPM malveillants

Analyse publiée le 27 août 2026 par la CyberProof Research Team, basée sur une découverte initiale de Microsoft Threat Intelligence en juillet…

🟢 vérification factuelle haute
#AsyncAPI #NPM #Cyberveille
Compromission de la chaîne d'approvisionnement AsyncAPI via des packages NPM malveillants
Analyse publiée le 27 août 2026 par la CyberProof Research Team, basée sur une découverte initiale de Microsoft Threat Intelligence en juillet 2026. L'incident concerne une compromission de la chaîne d'approvisionnement logicielle ciblant l'organisation NPM officielle AsyncAPI.
cyberveille.ch
August 28, 2026 at 1:30 PM
Supply chain attack on AsyncAPI's npm packages exposes developer credentials, urging enhanced security measures. #CyberSecurity #SupplyChainAttack #AsyncAPI #npm #DeveloperSecurity #CredentialTheft thedailytechfeed.com/asyncapi-sup...
July 29, 2026 at 11:31 AM
A critical supply chain attack hit official AsyncAPI npm packages, distributing credential-stealing malware. Attackers exploited a GitHub Actions misconfiguration, impacting millions of downloads. Learn how to protect your dev…

https://www.tpp.blog/1v7aqyc

#cybersecurity #asyncapi #npm
July 16, 2026 at 10:19 AM
📰 Serangan Supply Chain Infeksi Paket AsyncAPI di npm, Malware Curian Kredensial Sasar Developer

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/07/16/asyncapi-npm-malware-supply-chain-attack/

#asy
nc#asyncapir#cyberSecurityu#githubActionss#javascripta#malware.#nodepm ##npml#supplyChainA
July 16, 2026 at 7:43 AM
Five trojanized AsyncAPI npm packages were pushed through compromised GitHub Actions, stealing secrets, browser data, wallets, and CI/CD credentials via trusted publishing pipelines. #AsyncAPI #GitHubActions #npm
​ ​AsyncAPI npm packages infected with credential-stealing malware
Five malicious AsyncAPI packages were published to npm in a supply-chain attack that used compromised GitHub Actions workflows to deliver a remote access trojan with data-stealing capabilities. The attack affected widely used @asyncapi packages, leveraged legitimate publishing pipelines and SLSA attestations, and targeted secrets, browser data, wallets, and CI/CD credentials. #AsyncAPI #GitHubActions #npm #Miasma
www.hendryadrian.com
July 15, 2026 at 6:00 PM
— Explicación de lo que ha pasado con npm y AsyncAPI

AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads securityaffairs.com/195395/secur...

#infoSec #npm #AsyncAPI
AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads
AsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities.
securityaffairs.com
July 15, 2026 at 1:05 PM
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware thehackernews.com/2026/07/comp...

#asyncAPI #infoSec #dev # tech
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised AsyncAPI npm packages load a multi-stage botnet from IPFS after attackers abuse GitHub Actions, despite valid provenance attestations
thehackernews.com
July 15, 2026 at 12:04 PM
Valid SLSA provenance proved the workflow ran - not that the commit was clean. AsyncAPI's own pipeline shipped a RAT. https://intel.threadlinqs.com/threat/TL-2026-1360 #ThreatIntel #Miasma #AsyncAPI #M_Red_Team
July 15, 2026 at 9:51 AM
Compromised AsyncAPI packages on npm shipped malware after obfuscated JS was injected into the generator repo. Malicious versions hit @asyncapi/generator and related packages. #AsyncAPI #npm #OpenSource
Compromised AsyncAPI packages on npm deliver malware
A commit to the asyncapi/generator GitHub repository injected obfuscated JavaScript into source files across multiple packages, and four malicious versions were then published to npm on 2026-07-14. The active incident affects high-download packages including @asyncapi/generator, @asyncapi/generator-components, @asyncapi/generator-helpers, and @asyncapi/specs, with no revert, deprecation, or maintainer advisory published yet. #asyncapi/generator #asyncapi/specs
www.hendryadrian.com
July 14, 2026 at 6:30 PM
Four compromised packages in the @asyncapi npm namespace were found delivering a multi-stage loader that drops Miasma via IPFS, with persistence, REST C2, and fallback channels. #AsyncAPI #Miasma #GitHubActions
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
Socket’s Threat Research Team found four compromised AsyncAPI npm packages in the @asyncapi namespace that deliver a multi-stage loader leading to the Miasma payload from IPFS. The malicious releases were published through trusted publishing via GitHub Actions, but the poisoned source commit already contained the implant and the final framework includes persistence, REST C2, and multiple fallback channels. #AsyncAPI #Miasma #GitHubActions #IPFS
www.hendryadrian.com
July 14, 2026 at 6:00 PM
AsyncAPI npm packages backdoored via a GitHub Actions pwn-request - the RAT fires on import, not install. https://intel.threadlinqs.com/threat/TL-2026-1320 #ThreatIntel #Miasma #AsyncAPI #npm
July 14, 2026 at 5:07 PM
Security breach compromises AsyncAPI npm packages via GitHub Actions, affecting millions of downloads. #Security #AsyncAPI #npm #GitHubActions #SupplyChainAttack #DevSecOps thedailytechfeed.com/asyncapi-npm...
July 14, 2026 at 4:09 PM
A hidden pwn-request in AsyncAPI's CI let attackers hijack npm packages and drain dev secrets. https://intel.threadlinqs.com/threat/TL-2026-1299 #ThreatIntel #MRedTeam #Miasma #AsyncAPI
July 14, 2026 at 11:04 AM
🧩 Deel 3 (slot) van onze AsyncAPI-reeks is live.

AsyncAPI beschrijft wat er over de lijn gaat en waar. CloudEvents vult aan met hoe: een uniforme envelop met metadata (type, bron, id, timestamp).

Samen zijn ze een gelaagd model waar je makkelijk op ontwikkelt én implementeert. Handig bij […]
Original post on social.overheid.nl
social.overheid.nl
June 30, 2026 at 9:10 AM
Day 1 at FOST Amsterdam is underway! Lots of great sessions and discussions, plus a dedicated AsyncAPI track.

If you're attending, come say hello to the Kong team. Happy to chat about what you're building.

#FOSTAmsterdam #AsyncAPI #EventDrivenArchitecture #Kong
June 9, 2026 at 3:09 PM
One step further in defining a #SDLC for an event driven architecture using open standards and specifications like #jsonschema #cloudevents #asyncapi

Experimenting how good agents and tooling can generate code artifacts using models: JSON schema, CloudEvent definitions and a registry. So far 👌🏻
May 31, 2026 at 3:04 PM
🔄 Onze collega Floris Deutekom heeft de afgelopen maanden verkend of de AsyncAPI een bruikbare standaard is voor het specificeren van API's met asynchrone calls:
https://developer.overheid.nl/blog/2026/05/28/asyncapi-1-tot-nu-toe

Een tipje van de sluier: de tooling is erg volwassen, maar […]
Original post on social.overheid.nl
social.overheid.nl
May 28, 2026 at 2:02 PM