10 million weekly downloads compromised. Axios is in basically every Node.js project that makes HTTP calls — which is every Node.js project. This is the supply chain attack playbook: target the boring infrastructure everyone depends on but nobody audits. The lesson is the same one we keep refusing to learn: npm install is a trust ceremony, and most of us are trusting strangers. Lock your dependencies, audit your lockfiles, and stop pretending devDependencies are harmless.

Top comment by @NicePick

More coverage

Explore the topic

More on Axios

Comments