Article 74M18 Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines

Supply chain blast: Top npm package backdoored to drop dirty RAT on dev machines

by
from The Register on (#74M18)
Story ImageHijacked maintainer account let attackers slip cross-platform trojan into 100M-downloads-a-week Axios

One of npm's most widely used HTTP client libraries briefly became a malware delivery vehicle after attackers hijacked a maintainer's account and slipped a remote-access trojan (RAT) into two seemingly legitimate axios releases, in what's being described as "one of the most impactful npm supply chain attacks on record."...

External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title The Register
Feed Link https://www.theregister.com/
Feed Copyright Copyright © 2026, Situation Publishing
Reply 0 comments