Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client with 100M+ Weekly Downloads

A supply chain attack hit Axios when attackers used stolen npm credentials to publish malicious versions containing a phantom dependency. This triggered a cross-platform RAT during installation and replaced its files with clean decoys, making detection challenging.

原始链接: https://www.trendmicro.com/en_us/research/26/c/axios-npm-package-compromised.html
侵权请联系站方: [email protected]

相关推荐

换一批