Malware Attack Targets Axios npm Package, Affecting Millions
In a significant cybersecurity incident, hackers compromised the npm account of the popular Axios package, a JavaScript HTTP client with over 100 million weekly downloads. The attackers published two malicious versions of Axios, injecting remote access trojans (RATs) that target Linux, Windows, and macOS systems.
The attack occurred during a three-hour window, and with Axios’s widespread use, the number of affected projects is likely substantial. The malicious updates executed scripts that allowed the attackers to maintain control over infected systems, posing serious risks to users.
To protect against this threat, Axios users should revert to the last known safe versions, axios@1.14.0 and axios@0.30.3. Additionally, users are advised to rotate credentials and rebuild affected environments from a secure state.
Risk Level: High. This incident highlights the vulnerabilities in software supply chains, emphasizing the need for vigilance in software updates.
Source: View Original Report
