As cited
Copy frozen at (site build).
threat intel
Compromised axios npm package delivers cross-platform RAT
An attacker compromised an axios maintainer's npm account and published malicious releases containing a cross-platform remote access trojan (RAT). The compromised package affected users who installed the trojanized versions from the npm repository.
Why it matters: Developers and organizations using axios are at risk of code execution if they installed the affected releases; verify your dependencies and update to patched versions immediately.
- Source published
- First seen by Cybersecurity Tracker