AsyncAPI npm packages infected with credential-stealing malware
… As of writing, all five versions of the four malicious packages have been removed from npm, but developers should note that existing installations and lock files created during the exposure window may still contain the malicious releases. …