Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Delivered by Trust: What the Axios Supply Chain Attack Means for Security Leaders

Summary

Axios npm package compromised March 31, 2026: versions 1.14.1 and 0.30.4 carried a trojanized dependency that installs platform-specific RATs, enabling persistent access and hard-to-detect data theft.
Published
Collected

original ↗

Related coverage

back