Security teams are grappling with a major supply chain attack on Axios, a popular JavaScript library with over 100 million ...
Forty-five million weekly downloads. One compromised maintainer. Three hours of exposure before anyone noticed.
It's unclear how widespread the damage is from the recent axios hack involving North Korean malware, Microsoft Teams, Slack, ...
Axios is published and maintained on npm, the default package registry for JavaScript and Node.js projects. It is used to ...
Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
Threat actors hijacked the popular npm package axios to spread RAT malware after compromising an open‑source maintainer’s ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
Two CISOs dissect the Axios npm attack, revealing a self-erasing RAT, CI/CD compromise risks and why open-source software ...
Two versions of the widely used JavaScript library axios were maliciously published on npm on March 31, 2026. A hijacked ...
Axios functions as pre-built software that a developer can easily incorporate into a JavaScript project. However, a hacker ...
The NPM package for Axios, a popular JavaScript HTTP client library, was briefly compromised this week, possibly by North ...
A supply-chain attack backdoored versions of Axios, a popular JavaScript library that's present in many different software ...