Axios Maintainer Confirms The npm Compromise Was via a Targeted Social Engineering Attack
ID: 517ad163-2a03-5fa8-9130-eb234601742c
STIX ID: report--517ad163-2a03-5fa8-9130-eb234601742c
Feed Name: cybersecurityNews.com
Two malicious versions of the widely used npm package Axios (1.8.2 and 1.8.3) were briefly published with a hidden dependency that installed a cross-platform remote access trojan; the attacker gained access via an elaborate social-engineering compromise of the maintainer, stole active sessions and credentials, and thereby impacted thousands of downstream projects through transitive dependencies. Socket.dev discovered the packages and researchers recommend immediate audits and updates, adoption of hardware security keys, and tighter maintainer protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
