Two malicious versions of Axios were briefly published to npm on March 31 after a social engineering attack compromised maintainer Jason Saayman's machine. The attacker posed as a legitimate company, gained access to his device, hijacked browser sessions and cookies, and used his own credentials to publish a remote access

6m read timeFrom socket.dev
Post cover image
Table of contents
A Targeted Social Engineering Attack #The Burden on Solo Maintainers as Supply Chain Targets #

Sort: