« 2026

387 reports

2026-04-03 • Cisco Talos

Cisco Talos found that attackers published malicious Axios npm versions 1.14.1 and 0.30.4 on March 31, 2026, leaving the widely used JavaScript HTTP client exposed for about three hours. The modified packages introduced a fake dependency, plain-crypto-js,…

#NPM #Axios
2026-04-02 • Elastic

Elastic described detecting malicious axios npm releases through a monitoring pipeline that downloaded new package versions, diffed them against prior releases, and used an LLM to flag high-confidence supply-chain compromise. The malicious axios versions …

#NPM #Axios