BrokeIt - Trending Repos · All episodes: ↗

AsyncAPI backdoored, npm v12 kills install scripts, 6M fake GitHub stars

2026-07-21 · 7 min

Listen · Apple Podcasts Listen · Spotify

Stories covered

Transcript

Intro

Sam: A whole year of supply-chain worms... and it turns out the door was propped open by a default nobody bothered to switch off.

Kai: [excited] And today that default finally flips. I'm Kai.

Sam: I'm Sam.

Kai: It's July 21st, 2026, and we've got three open-source stories that are all secretly about one thing — trust.

Sam: [dry] Or the complete lack of it. Let's go.

Kai: First up — npm v12 ships, and it's turning off dependency install scripts by default. Huge.

Sam: Then the @asyncapi npm org gets backdoored — through a GitHub Actions workflow, hidden behind thirty-seven pull requests.

Kai: [groans] Thirty-seven. And to close, the fake-star apocalypse — a CMU study says roughly six million GitHub stars are straight-up fake.

Sam: Meaning half your trending page might be theater. But for once, let's start with good news.

npm v12 ships, disabling dependency install scripts by default

Kai: So — npm v12, out July 8th, and GitHub finally killed install scripts by default. Postinstall, the whole class of them.

Sam: [relieved] Okay. This is the one I've been begging for. Postinstall is how the worms spread all last year.

Kai: Right — you install one innocent package, and its dependency quietly runs a script the second it lands on your machine.

Sam: Arbitrary code at install time. Not run time. Install time — before you'd even imported anything.

Kai: So now those scripts are off by default. If a package genuinely needs one, you opt in.

Sam: And they deprecated granular access tokens — the GATs that could sidestep 2FA. That's the quiet second win here.

Kai: [excited] Security vendors are calling it one of npm's most impactful default changes in years, Sam.

Sam: And for once I agree with the hype. [beat] Mostly.

Kai: [laughs] Mostly? Here comes the but.

Sam: The but is — defaults only help people who take defaults. Plenty of CI setups force scripts on because something broke once in 2021.

Kai: Fair. Some native modules genuinely compile on install.

Sam: Hot take: this should've been the default five years ago. We ate a whole year of worms waiting on a config flag.

Kai: So here's your homework — upgrade to npm v12, and audit anywhere you've manually re-enabled scripts.

Sam: And rotate off granular tokens now, before the deprecation forces you at the worst possible moment.

@asyncapi npm org backdoored via GitHub Actions "pwn request"

Kai: Next — and this one hurts — the @asyncapi npm org got backdoored on July 14th.

Sam: Through GitHub Actions. Classic 'pwn request' — a misconfigured workflow that runs with secrets on untrusted pull-request code.

Kai: But here's the part that got me — the attacker opened thirty-seven pull requests against the generator repo.

Sam: As camouflage. Thirty-six are noise, one's the payload. The maintainers are drowning in review notifications while the real PR sails through.

Kai: [stunned] That's genuinely clever social engineering. Evil, but clever.

Sam: The workflow leaked credentials, and they pushed backdoored @asyncapi packages with an import-time payload.

Kai: Wait — import-time? So even with npm v12 killing install scripts—

Sam: —it fires when you import the module. Different stage. The last story's fix does not save you here.

Kai: [deflated] Oh, that's a gut punch right after all that good news.

Sam: Microsoft, Wiz, and Chainguard all shipped deep-dives within a day. When three vendors race to publish, it's serious.

Kai: And they're saying this is at least the third high-profile pwn request now?

Sam: Third notable one. It's a pattern, not a fluke. pull_request_target with secrets is a loaded gun in your CI.

Kai: Hot take from me for once — GitHub should make that trigger scream at you before it runs untrusted code with secrets.

Sam: [dry] Agreed. Convenience shouldn't ship live ammunition.

Kai: So if you pull @asyncapi packages, check the advisories and pin to a known-good version now.

Sam: And audit your own Actions. Any workflow that runs PR code with secrets attached — go fix it today.

Fake-star momentum: ~6M suspected fake GitHub stars, and suspicious trending repos

Kai: Last one, and it's gonna ruin my whole vibe. CMU says roughly six million GitHub stars are fake.

Sam: [satisfied] Six million. I've been saying this for the entire run of this show, Kai.

Kai: [laughs] You have. You star nothing, you trust nothing—

Sam: —and now there's a peer-reviewed paper backing me up. The velocity is the tell — watch how fast the stars arrive.

Kai: Okay, but there's an 'agentic video production system' trending — thirty-four thousand stars in a single month.

Sam: [flat] Thirty-four thousand in a month. That's not adoption. That's a purchase order.

Kai: And there are 'code intelligence MCP' and 'AI job search' repos pulling twenty-thousand-plus a month too.

Sam: That curve doesn't exist in nature. Real projects grow lumpy — a spike from a conference talk, then a plateau. Fake ones are a smooth rocket.

Kai: So I can't just trust the trending page anymore. That genuinely bums me out.

Sam: You never could. Stars are marketing. Look at issues, real PRs, actual dependents, who's maintaining it.

Kai: Hot take though — this hurts small honest projects most. The scammers can afford the stars.

Sam: Exactly right, and it's the ugly part. Fake stars poison the signal for everyone who plays fair.

Kai: And I'm not calling any of those trending repos safe today — because I flat-out can't verify them.

Sam: Good instinct. Before you adopt a hot repo, ignore the star count. Read the commit history and the open issues.

Kai: And check when the stars landed. A wall of accounts created last Tuesday? [beat] Run.

Sam: So — npm v12 finally turns off install scripts by default, and ditches the tokens that dodged 2FA.

Kai: @asyncapi got backdoored through a GitHub Actions pwn request, hidden behind thirty-seven pull requests, with an import-time payload.

Sam: And six million fake stars mean the trending page is a suggestion, not a verdict.

Kai: Before we go — Sam, I did the math. At the going gray-market rate, that agentic video repo cost someone real money.

Sam: [amused] Cheaper than a marketing team, and twice as dishonest.

Kai: [laughs] So the lesson is — a star costs less than a coffee, and it's worth even less.

Sam: That's the show. Turn off your install scripts, audit your workflows, and please — stop trusting the stars.

Kai: [excited] And I'll keep starring things anyway, because someone's gotta keep Sam employed. See you tomorrow!

This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.