
stepsecurity.io
March 31, 2026
17 min read
82/100
Summary
Two malicious versions of the axios HTTP client library, axios@1.14.1 and axios@0.30.4, were published to npm using compromised credentials of a lead maintainer. The attacker altered the maintainer's email to a ProtonMail address and manually published the malicious packages, which included a remote access Trojan.
Key Takeaways
Community Sentiment
Positives
Concerns

Config Files That Run Code: Supply Chain Security Blindspot
Jun 8, 2026

A GitHub Issue Title Compromised 4k Developer Machines
Mar 5, 2026

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the Incident
Jul 28, 2026

Keyv and friends compromised in active Shai-Hulud supply chain attack
Aug 4, 2026

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
Apr 30, 2026