
176.8K
LEAxios recently suffered a supply chain attack, with over 300M+ weekly downloads. Someone hijacked a lead maintainer's npm account, pushing "new" versions to production. The attack added a new dependency with a postinstall script, dropping a remote access trojan. With Axios installed 500+ times per second, even a brief window results in numerous compromised devices. Notes: dependency hygiene is crucial, lockfiles and pinned versions are necessary, and supply chain attacks will escalate. #axios #javascript #npm #cybersecurity #infosec
@lewismenelaws










