A supply-chain attack backdoored versions of Axios, a popular JavaScript library that's present in many different software ...
'This is unironically a malware nuclear missile.' ...
The Tool Lending Library is a free program that gives PG&E customers access to a wide range of professional‑grade energy and ...
Attackers stole a long-lived npm token from the lead axios maintainer and published two poisoned versions that drop a ...
Axios is published and maintained on npm, the default package registry for JavaScript and Node.js projects. It is used to ...
In 2025, Google fixed a total of eight zero-days exploited in the wild, many of which were discovered and reported by ...
It is exactly this backdoor that had Google conclude this was a North Korea-sponsored campaign. GTIG said WAVESHAPER.V2 is an ...
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
According to Google researchers, a North Korean group tracked as UNC1069 has previously targeted cryptocurrency and ...
The malicious releases were available for about three hours before they were removed, but the brevity of the window has done little to calm alarm because Axios is one of the most heavily used HTTP ...
Overview On March 31, NSFOCUS CERT detected that the npm repository of the HTTP client library Axios was poisoned by the supply chain. The attacker bypassed the normal GitHub Actions CI/CD pipeline of ...
A North Korea-nexus threat actor compromised the widely used axios npm package, delivering a cross-platform remote access ...