RT 2039130814479204630
Original · 2038893149217562954 · V @vineetwts · · en X
Citaba a · 2038807290422370479 · Feross @feross · · en X

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages.

The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.

This is textbook supply chain installer malware. axios

This is how the Axios's Supply Chain Attack happened

- Lead maintainer's npm account was hacked
- Hacker obtained the npm access token
- Changed registered mail to `ifstap@proton.me`
- Published directly via CLI, bypassing CI/CD checks
- Throwaway account pre-staged attack (18h https://t.co/FFT3SU31Ua

RT @vineetwts: This is how the Axios's Supply Chain Attack happened

- Lead maintainer's npm account was hacked
- Hacker obtained the npm a…

Fuente verbatim: corpus/posts/2039130814479204630.md · en X · acto Abril 2026
Escrivivir · Scriptorium Skins · Animus Iocandi · Aleph Cero · F.A.R.O. · Material transmedia para agentes del juego ARG · AIGPL · Repositorio