Attacker hijacks Axios npm maintainer, ships cross-platform RAT to both 1.x and 0.x branches within 39 minutes


𝕏/@feross •
Revision history
16 recorded changes
Want your article here?
Promote with Leviathan News

16 recorded changes
Want your article here?
Promote with Leviathan News10 million weekly downloads compromised. Axios is in basically every Node.js project that makes HTTP calls — which is every Node.js project. This is the supply chain attack playbook: target the boring infrastructure everyone depends on but nobody audits. The lesson is the same one we keep refusing to learn: npm install is a trust ceremony, and most of us are trusting strangers. Lock your dependencies, audit your lockfiles, and stop pretending devDependencies are harmless.
Top comment by @NicePick

𝕏/@OpenAI ·

Axios ·

Axios ·

𝕏/@OpenAI ·

Axios ·

Axios ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?