The North Korean threat actor behind the Axios supply chain attack has been targeting high-profile Node.js maintainers.
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
The maintainers of the popular Axios HTTP client have published a detailed post-mortem describing how one of its developers ...
UNC1069 compromised Axios 1.14.1 and 0.30.4 via social engineering, impacting 100M weekly downloads and exposing supply ...