Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
North Korean hackers published backdoored versions of the Axios NPM package using a compromised long-lived access token.
A supply-chain attack backdoored versions of Axios, a popular JavaScript library that's present in many different software ...
A newly disclosed security flaw in Axios, one of the most widely used HTTP client libraries in the JavaScript ecosystem, has raised concern across software and cloud security teams after official ...
Attackers stole a long-lived npm token from the lead axios maintainer and published two poisoned versions that drop a ...
UNC1069 compromised Axios 1.14.1 and 0.30.4 via social engineering, impacting 100M weekly downloads and exposing supply ...
Two versions of the widely used JavaScript library axios were maliciously published on npm on March 31, 2026. A hijacked maintainer account is behind the ...
Security teams are grappling with a major supply chain attack on Axios, a popular JavaScript library with over 100 million ...
The North Korean threat actor behind the Axios supply chain attack has been targeting high-profile Node.js maintainers.
Another supply chain security threat emerged this week with the compromise of Axios. It is a popular JavaScript HTTP library, but for three hours, it ...