ended3월 31일· 7 sources
Critical NPM Supply Chain Breach: Popular axios Library Weaponized for Malware Distribution
axios NPM 공급망 공격, 원격 접근 트로잔 배포로 수백만 개발자 위협
Why it matters
Popular HTTP client library axios was compromised via stolen NPM maintainer credentials, distributing a remote access trojan to millions of developers. This supply chain attack underscores critical vulnerabilities in open-source dependency management and the effectiveness of social engineering targeting developer accounts.
7
Sources
+0
24h
—
Growth
174d
Active
axiosmaintainer risksocial engineeringcredential theftremote access trojansecretsnpm security
Sources
devto
How the [email protected] supply chain attack worked (and how to protect yourself)4월 3일
reddit_progaxios 1.14.1 and 0.30.4 on npm are compromised - dependency injection via stolen maintainer account3월 31일
devtonpm package commitment scores: zod has 139M weekly downloads and one maintainer4월 5일
devtoThe Axios Attack Proved npm audit Is Broken. Here's What Would Have Caught It4월 6일
hackernewsAxios Compromised on NPM – Malicious Versions Drop Remote Access Trojan3월 31일
devtoURGENT: The Axios npm Package Was Just Compromised!4월 4일
hackernewsPost Mortem: axios NPM supply chain compromise4월 3일