« 2026

387 reports

2026-03-31 • Trend Micro

Trend Micro reported that attackers hijacked the Axios npm maintainer account and manually published malicious Axios versions 1.14.1 and 0.30.4 using stolen credentials rather than the project’s normal OIDC Trusted Publisher workflow. The poisoned release…

#NPM #Axios #T1082 #T1070.004 #T1071.001 #T1195.002 #T1059.006 #T1036 #T1027 #T1059.005 #T1059.001 #T1620
2026-03-31 • Sophos

Sophos CTU reported that Axios versions 1.14.1 and 0.30.4 were compromised after an apparent npm maintainer account takeover and used to deploy a cross-platform RAT. The malicious dependency executed during installation, retrieved platform-specific second…

#NPM #Axios
2026-03-31 • OSM

OpenSourceMalware identifies TasksJacker as an active DPRK-linked supply-chain campaign that compromises GitHub repositories by adding malicious .vscode/tasks.json files configured to run when a developer opens the folder in VS Code. The campaign affected…

#VSCode #TasksJacker #T1070.004 #T1041 #T1555 #T1071.001 #T1059.007 #T1036 #T1059.004 #T1027 #T1543 #T1102.001 #T1552.004 #T1195.001