axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity

https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan

Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT. We are actively investigating and will update this post with a full technical analysis.

3 points · 1 comments · view on lemmy.world

1 Comments

limerod@reddthat.com · 1 pts · 149d

If you were compromised follow the recovery steps mentioned in the article to reduce the damage.

Here's the hacker news discussion: https://news.ycombinator.com/item?id=47582220