Attackers stole a long-lived npm token from the lead axios maintainer and published two poisoned versions that drop a ...
TeamPCP strikes again, with almost identical code to LiteLLM.
North Korean hackers published backdoored versions of the Axios NPM package using a compromised long-lived access token.
Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
Two versions of the widely used JavaScript library axios were maliciously published on npm on March 31, 2026. A hijacked ...
Supply chain attacks feel like they're becoming more and more common.
The popular, open source Nuget Package Management system makes quick work of installing, configuring and updating third-party components in.NET projects. Welcome to the new Open Source .NET column at ...