Last Updated: 2026-07-14T22:16:54Z
What’s Happening
I was trying to come up with a framing for this story other than “Oh look another supply chain attack, whoopty-doo.”
But yeah, asyncapi packages were hit today.
Actions
Of course you want to do the usual package checks, rotations, say three Hail Marys, turn around three times and throw salt over your shoulder. But also, this payload presents some good reminders about goofy attacker techniques that should not survive a mature network.
Instead of a preinstall or postinstall hook, this attack uses a straight-up malicious script in the package. Then it uses IPFS for a second stage source, and a combination of IPFS, Etherhiding, and…Nostr?? for command and control.
None of that should work on your network. Extremely few people have legitimate business uses for these technologies. Don’t let them function in your walls.
So at the very least, block:
ipfs[.]iorelay.damus[.]io*.damus.io, reallyrelay.nostr[.]com*.nostr[.]comwhile you’re at it
Notes
Funny how DHTs continue to support the worst parts of the internet.
Does that include ATProto??
