ended6월 14일· 1 sources

Widely-Used axios Library Compromised in Major npm Supply Chain Attack

npm 공급망 공격, 주간 1억 다운로드 axios 악성코드 감염

Why it matters

With 100 million weekly downloads, axios is one of JavaScript's most critical HTTP libraries, making its compromise through an npm supply chain attack a major threat to frontend applications, backend services, and enterprise systems worldwide. Attackers exploited a hijacked npm token to publish malicious versions containing a multi-stage remote access trojan capable of executing arbitrary commands and exfiltrating sensitive data and environment secrets. Developers who installed affected versions (1.14.1 and 0.30.4) must immediately treat their machines as compromised and rotate all credentials to prevent unauthorized access.

1
Sources
+0
24h
Growth
98d
Active
axiossupply chain attackmalicious dependencyRemote Access Trojancredential rotation

Sources

Related Issues