
stepsecurity.io
March 31, 2026
17 min read
82/100
Summary
Two malicious versions of the axios HTTP client library, axios@1.14.1 and axios@0.30.4, were published to npm using compromised credentials of a lead maintainer. The attacker altered the maintainer's email to a ProtonMail address and manually published the malicious packages, which included a remote access Trojan.
Key Takeaways
Community Sentiment
Positives
Concerns

Config Files That Run Code: Supply Chain Security Blindspot
Jun 8, 2026

A GitHub Issue Title Compromised 4k Developer Machines
Mar 5, 2026

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
Apr 30, 2026

We May Be Living Through the Most Consequential Hundred Days in Cyber History
Apr 13, 2026

Anatomy of a Failed (Nation-State?) Attack
Jun 27, 2026