Reading List
axios Compromised on NPM from Michael Tsai RSS feed.
axios Compromised on NPM
Ashish Kurmi (Hacker News): axios is the most popular JavaScript HTTP client library with over 100 million weekly downloads. On March 30, 2026, StepSecurity identified two malicious versions of the widely used axios HTTP client library published to npm: axios@1.14.1 and axios@0.30.4. The malicious versions inject a new dependency, plain-crypto-js@4.2.1, which is never imported anywhere […]