Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT
On March 31, 2026, two malicious versions of axios, the enormously popular JavaScript HTTP client with over 100 million weekly downloads, were briefly published to npm via a compromised maintainer account. The packages contained a hidden dependency t...
snyksec.hashnode.dev9 min read