Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan ...
Anthropic says it accidentally leaked the source code for Claude Code, which is closed source, but the company says no ...
One of the most popular ways to view the Epstein Files, an interface called Jmail that mimics a Gmail inbox, is hosted on ...
How can an extension change hands with no oversight?
A critical supply chain attack has compromised the popular JavaScript library axios, leading to developers unknowingly ...
With almost 175,000 npm projects listing the library as a dependency, the attack had a huge cascade effect and shows how ...
The group Everytown for Gun Safety used court records to trace more than 250 guns bought at nearly two dozen Academy Sports + ...
Spotify and major record labels are seeking a $322 million default judgment from Anna’s Archive, which hasn’t responded to ...
The Justice Department has released more documents from the Jeffrey Epstein files related to allegations against President Trump, a move that came after the department was pressured to review its ...
Active exploits, nation-state campaigns, fresh arrests, and critical CVEs — this week's cybersecurity recap has it all.