NPM Package Supply Chain Compromise Leads to RAT Deployment
Reported 10 Apr 2026 by otx · Severity: medium
A supply chain attack targeting the Axios npm package has been identified after threat actors compromised the npm account of the company's lead developer. Malicious versions (axios@1.14.1 and axios@0.30.4) were published containing a hidden dependency that executed postinstall sc