The widely used Axios HTTP client library, a JavaScript component used by developers, was recently hacked to distribute malware via a compromised account. Attackers exploited a hijacked account on npm ...
Security teams are grappling with a major supply chain attack on Axios, a popular JavaScript library with over 100 million weekly downloads. The North Korean state actor Sapphire Sleet compromised the ...
A supply-chain attack affecting Axios, the popular JavaScript library, traced back to DPRK threat activity. (Image: Shutterstock) A supply-chain attack that compromised versions of Axios to distribute ...
On March 30, 2026, the JavaScript ecosystem faced a massive software supply chain attack. Axios, the most popular HTTP client with over one hundred million weekly downloads, was weaponized to deliver ...
Security companies flagged axios@1.14.1 and 0.30.4 as compromised, urging credential rotation and rollback of affected packages. Update March 31, 2026, 1:28 pm UTC: This article has been updated to ...
On March 31, the cybersecurity community faced a major scare when two malicious versions of Axios, a wildly popular JavaScript library, were briefly published to the npm registry. These compromised ...
An attacker compromised the npm account of axios maintainer jasonsaayman and published two malicious versions of the widely-used JavaScript HTTP client library on March 31, 2026. The poisoned packages ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results