Introduction: The Axios Compromise


Yesterday, the npm ecosystem was jolted by the discovery of malicious versions of Axios (1.14.1 and 0.30.4), published through a compromised maintainer account. These versions bypassed the standard GitHub Actions release pipeline, introducing a backdoor via the plain-crypto-js dependency. The mechanism of...