Axios NPM Distribution Compromised in Supply Chain Attack
Summary
A hacked axios maintainer published malicious npm versions 1.14.1/0.30.4 carrying plain-crypto-js, a dropper planting platform RATs. Pulled within hours, yet axios runs in ~80% of cloud environments.
- Published
- Collected
Skip to content