Home / Security updates / Datadog's Response to Compromised AsyncAPI npm Packages
Datadog's Response to Compromised AsyncAPI npm Packages
Security updates detail rendered from /security-updates/upd_83215ca1d3c1b5f4.
Overview
| ID | upd_83215ca1d3c1b5f4 |
| Collection | Security Updates |
| Provider | SafeBase |
| Company | Datadog |
| URL | - |
| Counts | - |
| Updated | - |
Raw record
| Field | Value |
|---|---|
| id | upd_83215ca1d3c1b5f4 |
| providerId | safebase |
| organizationId | org_69291cebe8d5d66e |
| trustCenterId | tc_3aed993e7dda3cf3 |
| title | Datadog's Response to Compromised AsyncAPI npm Packages |
| message | We are aware of a supply chain attack in which four npm packages published by the AsyncAPI open source project, were compromised with malicious code on July 14, 2026: - @asyncapi/generator - @asyncapi/generator-helpers - @asyncapi/generator-components - @asyncapi/specs Upon learning of this activity, Datadog's security team immediately investigated our potential exposure. As a result, we can confirm Datadog does not use any of the affected packages in our products or infrastructure. As an added precaution, we have blocked all known malicious versions of these packages, along with associated network infrastructure, across our internal systems. For a detailed breakdown of the campaign and how you can assess impact in your own environment, refer to our [Security Labs post](https://securitylabs.datadoghq.com/articles/compromised-asyncapi-npm-packages/). If you have any further questions, our [Support team](https://www.datadoghq.com/support/) is here to help. |
| url | - |
| publishedAt | 2026-07-15 |
| source | {
"field": "statuspage/public/compliance-update",
"category": "incidents"
} |
| company | {
"id": "org_69291cebe8d5d66e",
"name": "Datadog",
"domains": [
"trust.datadoghq.com",
"datadoghq.com"
]
} |
| trust_center | {
"id": "tc_3aed993e7dda3cf3",
"name": "Datadog",
"url": "https://trust.datadoghq.com",
"host": "trust.datadoghq.com"
} |
| provider | {
"id": "safebase",
"name": "SafeBase"
} |
| links | {
"self": "/v1/security-updates/upd_83215ca1d3c1b5f4",
"company": "/v1/companies/org_69291cebe8d5d66e",
"trust_center": "/v1/trust-centers/tc_3aed993e7dda3cf3",
"provider": "/v1/providers/safebase"
} |
Get this page with API
Rendered from the bluedoor Trust Centers API. Reproduce it:
GET https://api.bluedoor.sh/trust-centers/v1/security-updates/upd_83215ca1d3c1b5f4JSON