|
Canada-0- Company Direktoryo
|
Company News :
- Axios NPM Package Compromised: Supply Chain Attack Hits . . .
Axios, a widely used JavaScript HTTP client with over 100 million weekly npm downloads, was compromised when an attacker hijacked the lead maintainer’s npm account and published two malicious versions (1 14 1 and 0 30 4) that deployed a cross-platform remote access trojan (RAT)
- Axios npm attack: rapid hunting with KQL and response guide . . .
In this blog post, we briefly walk through the details of the incident, share our observations, and provide KQL hunting queries used to identify and assess exposure across our MDR customers Brief Incident Summary An adversary obtained access to the lead maintainer’s npm account and managed to publish two Axios versions (1 14 1 and 0 30 4)
- axios Was Compromised on npm — What Happened, How It Works . . .
This article walks you through exactly what happened, how the attack technically works, how to check if you're compromised, and what permanent changes you should make to your workflow The operation was pre-staged 18 hours in advance This was not opportunistic Every artifact was purpose-built
- Axios npm Package Compromised: Supply Chain Attack . . . - Snyk
On March 31, 2026, two malicious versions of axios, the enormously popular JavaScript HTTP client with over 100 million weekly downloads, were briefly published to npm via a compromised maintainer account
- axios Compromised on npm - Malicious Versions Drop Remote . . .
The attacker compromised the jasonsaayman npm account, the primary maintainer of the axios project The account’s registered email was changed to ifstap@proton me — an attacker-controlled ProtonMail address
- Post Mortem: axios NPM supply chain compromise - GitHub
Hyper vigilance is needed both on the registry and in a personal capacity Summary for broarder audience We can confirm that two compromised versions of Axios were briefly made available through a widely used software download system due to unauthorized access to the lead maintainer's account, not a change to the underlying code
- Inside the Axios supply chain compromise - one RAT to rule . . .
The attacker gained control of the npm account belonging to jasonsaayman, one of the project's primary maintainers, and published two backdoored versions within a 39-minute window
|
|