Four supply-chain attacks hit npm/PyPI (Jun–Jul 2026): Miasma/Hades worm, IronWorm, fake payment SDKs & AsyncAPI CI token theft. All stole credentials; AsyncAPI packages (2.25M+ weekly downloads) carr
Four supply-chain attacks hit npm/PyPI (Jun–Jul 2026): Miasma/Hades worm, IronWorm, fake payment SDKs & AsyncAPI CI token theft. All stole credentials; AsyncAPI packages (2.25M+ weekly downloads) carried valid Sigstore signatures. https:// threatintel.cc/2026/07/27/the- streak-continues-four-more.html