Diamond Member ThaHaka 0 Posted March 31 Diamond Member Share Posted March 31 This is the hidden content, please Sign In or Sign Up The popular HTTP client known as Axios has suffered a supply chain attack after two newly published versions of the npm package introduced a malicious dependency. Versions 1.14.1 and 0.30.4 of Axios have been found to inject "plain-crypto-js" version 4.2.1 as a fake dependency. According to StepSecurity, the two versions were published using the compromised npm credentials of the primary Axios This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/307116-h4ckn3wsaxios-supply-chain-attack-pushes-cross-platform-rat-via-compromised-npm-account/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.