ended3월 31일· 7 sources

Critical NPM Supply Chain Breach: Popular axios Library Weaponized for Malware Distribution

axios NPM 공급망 공격, 원격 접근 트로잔 배포로 수백만 개발자 위협

Why it matters

Popular HTTP client library axios was compromised via stolen NPM maintainer credentials, distributing a remote access trojan to millions of developers. This supply chain attack underscores critical vulnerabilities in open-source dependency management and the effectiveness of social engineering targeting developer accounts.

7
Sources
+0
24h
Growth
174d
Active
axiosmaintainer risksocial engineeringcredential theftremote access trojansecretsnpm security

Sources

Related Issues