The widely used Axios HTTP client library, a JavaScript component used by developers, was recently hacked to distribute malware via a compromised account. Attackers exploited a hijacked account on npm ...
The Axios JavaScript NPM package was recently compromised, representing one of the highest impact supply chain attacks against the open source development ecosystem in recent months. Axios is the most ...
On March 30, 2026, with an account using a separate throwaway ProtonMail address, the attacker published on NPM a trojanized copy of the popular crypto-js JavaScript library of crypto standards. This ...
Security companies flagged axios@1.14.1 and 0.30.4 as compromised, urging credential rotation and rollback of affected packages. Update March 31, 2026, 1:28 pm UTC: This article has been updated to ...
米Amazonの脅威調査チームは、Node Package Manager(npm)ライブラリの4つの異なる改ざんについて、北朝鮮政府が支援する脅威アクターによるものだと高い確信を持って断定した。 バージニア州 ...
Atacantes ligados à Coreia do Norte criaram uma empresa falsa no Slack, agendaram uma reunião e enganaram o mantenedor ...