Top npm package backdoored to drop dirty RAT on dev machines
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Attackers hijacked the npm account of axios's primary maintainer and published two malicious versions (axios@1.14.1 and axios@0.30.4) containing a remote-access trojan. The compromise bypassed GitHub Actions CI/CD by pushing packages manually via the npm CLI after swapping the account's email. A rogue dependency,
Sort: