Critical Backdoor Discovered in axios Package (heise.de)
0xBASE INTEL BRIEF
- Maintainer account hijacked on the npm registry
- Injection of a multi-platform Remote Access Trojan
- Impacts millions of global web and server applications
"The widely used axios npm package has been compromised following a maintainer account takeover. Attackers injected a cross-platform Remote Access Trojan (RAT) targeting Windows, macOS, and Linux. This represents a major supply chain security failure for the JavaScript ecosystem."
no comments yet.