Introduction: The Axios Compromise
Yesterday, the npm ecosystem was jolted by the discovery of malicious versions of Axios (1.14.1 and 0.30.4), published through a compromised maintainer account. These versions bypassed the standard GitHub Actions release pipeline, introducing a backdoor via the plain-crypto-js dependency. The mechanism of...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3372201