Original · 2038893149217562954 · V @vineetwts · · en X
Citaba a · 2038807290422370479 · Feross @feross · · en X
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios
This is how the Axios's Supply Chain Attack happened
- Lead maintainer's npm account was hacked - Hacker obtained the npm access token - Changed registered mail to `ifstap@proton.me` - Published directly via CLI, bypassing CI/CD checks - Throwaway account pre-staged attack (18h https://t.co/FFT3SU31Ua
RT @vineetwts: This is how the Axios's Supply Chain Attack happened
- Lead maintainer's npm account was hacked - Hacker obtained the npm a…