As cited
Copy frozen at (site build).
vulnerabilities
Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads
Attackers used compromised npm credentials to publish malicious versions of the widely used Axios HTTP client library. The poisoned packages installed a remote access trojan (RAT) that executed during setup, while the library's legitimate files were replaced with clean decoys to evade detection.
Why it matters: JavaScript developers and organizations using Axios across projects face immediate risk of system compromise; practitioners should audit npm dependencies, check installation logs, and review the npm security advisory for affected versions and remediation steps.
- Source published
- First seen by Cybersecurity Tracker