🤔 axios Package Compromised; Malicious Versions Added a Trojan Dependency
Axios is an HTTP library that gets 100M+ downloads a week, largely due to its legacy popularity. An attacker took advantage of that to roll out a version with a malicious dependency including a remote access trojan (though Axios' codebase itself was fine). This is big, as even if you don’t use Axios, your dependencies might. Here's how to see if you're affected.
Ashish Kurmi
Post #3111
3.04K

- ❤ 4
- 🔥 4
- 🤔 3
- 🤩 1