GeistHaus
log in · sign up

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

thehackernews.com

Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying cross-platform RAT malware.

4 pages link to this URL
» north korean hacker group UNC1069 using social engineering to get access: axios npm for nodejs: software minimalism please and another javascript security problem (this time social engineered supply chain attack)

Why keep all your results to yourself? - Blog with howtos and public free software and hardware OpenSource searchable knowledgebase about Linux and OpenSource - with a touch security, politics and philosophy.

0 inbound links en OpenSourceOpenSourceLinuxalternativasAndroidPHPTerminalBashScriptsGNUMySQLLinux-GNUDebianhackingHardwareinternetApplePolitikpoliticsSicherheitsecuritycybersecuritycyberencryptionhacktivismSPAMmailserverdatabasecybercrimefailfsfgnometechnologymailserverSoftwarestartupsstoragefilesystemsvirtualboxvirtualizationWebDevHTMLWebDevelopmentwordpressphilosophyunix CC BY-ND 3.0