Axios NPM Distribution Compromised in Supply Chain Attack
Reported 31 Mar 2026 by otx · Severity: medium
An unknown threat actor compromised the npm account of an axios maintainer, publishing two malicious versions of the package. These versions introduced a dependency on plain-crypto-js, a newly created malicious package. Despite quick removal, axios's widespread usage led to rapid