On March 31, 2026, attackers compromised an axios npm maintainer account and published two backdoored versions (1.14.1 and 0.30.4) containing a malicious dependency called plain-crypto-js. This dependency runs a postinstall script that downloads and executes a remote access trojan on macOS, Windows, and Linux, then erases its

6 Comments

Sort: