StepSecurity's AI Package Analyst and Harden-Runner detected the compromise of axios — the most downloaded npm package with 100M+ weekly downloads — in real time before any public disclosure. The malicious versions (1.14.1 and 0.30.4) contained a hidden dependency that installed a remote access trojan and phoned home to a C2

14m read timeFrom stepsecurity.io
Post cover image
Table of contents
The AlertVerifying the UnknownSounding the AlarmThe Threat Actor Strikes BackWorking With the CommunityThe Ripple EffectMedia CoverageA Community ConfirmationThe Bigger Picture

Sort: