The North Korean threat actor behind the Axios supply chain attack has been targeting high-profile Node.js maintainers.
Axios, a widely used JavaScript HTTP client, was briefly distributed through npm in two malicious versions after a maintainer ...
A supply-chain attack backdoored versions of Axios, a popular JavaScript library that's present in many different software ...
The NPM package for Axios, a popular JavaScript HTTP client library, was briefly compromised this week, possibly by North ...
Security teams are grappling with a major supply chain attack on Axios, a popular JavaScript library with over 100 million ...
Security firm Socket advised developers to check dependencies for affected Axios versions and remove or roll back compromised ...
A large-scale campaign is targeting developers on GitHub with fake Visual Studio Code (VS Code) security alerts posted in the ...
The maintainers of the popular Axios HTTP client have published a detailed post-mortem describing how one of its developers ...
UNC1069 compromised Axios 1.14.1 and 0.30.4 via social engineering, impacting 100M weekly downloads and exposing supply ...
Socket uncovers large-scale GitHub spam campaign abusing “Discussions” notifications Fake advisories with bogus CVEs trick ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results