Millions of JS devs just got penetrated by a RAT…

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Two malicious versions of Axios were published to the npm registry containing a sophisticated supply chain attack. The attacker compromised the project maintainer's npm account and injected a rogue dependency (plain-crypto-js) that runs a post-install script to download a Remote Access Trojan (RAT) from a command-and-control

4m watch time

Sort: