GeistHaus
log in · sign up

Post Mortem: axios npm supply chain compromise · Issue #10636 · axios/axios

github.com

Post Mortem: axios npm supply chain compromise Date: March 31, 2026 Author: Jason Saayman Status: Remediation in progress On March 31, 2026, two malicious versions of axios (1.14.1 and 0.30.4) were...

14 pages link to this URL
Simon Willison on open-source

304 posts tagged ‘open-source’.

0 inbound links website en ai 2024generative-ai 1791llms 1757python 1250django 588quora 1005javascript 755local-llms 156github 187ai-assisted-programming 383
#771 Compromised

The author's work laptop was compromised by a foreign actor. This post details how their company's security tools caught the attack and prevented a disaster.

0 inbound links article en security
Le podcast Java en Français

Les Cast Codeurs est un podcast en français de, par et pour les développeurs. Prenez connaissance des dernières nouvelles de la sphère Java et du développement en général. Plongez sur un sujet précis avec les épisodes interview.

0 inbound links website fr https://github.com/tginsberg/gatherers4j/releases/tag/v0.13.0https://github.com/langchain4j/langchain4j/releases/tag/1.10.0https://github.com/testcontainers/testcontainers-java/releases/tag/2.0.0
Weakly Link 26/14

This week we have a look at the current chaos. Be it political or technical, we’re going through some radical changes. And I can’t help but think, if this is what progress looks like, oh crap. Supply Chain Chaos We start by having a look at an article by Ian about the Mad Emperor. No prizes for guess who is meant there. From the outside in, it really looks like there’s no plan or no idea about the kind of problems the attack on Iran is causing.

0 inbound links article en posts
Simon Willison on security

602 posts tagged ‘security’.

0 inbound links website en ai 2016llms 1751generative-ai 1785prompt-injection 147xss 60exfiltration-attacks 43javascript 755csrf 54phishing 54python 1250