
stepsecurity.io
March 31, 2026
17 min read
82/100
Summary
Two malicious versions of the axios HTTP client library, axios@1.14.1 and axios@0.30.4, were published to npm using compromised credentials of a lead maintainer. The attacker altered the maintainer's email to a ProtonMail address and manually published the malicious packages, which included a remote access Trojan.
Key Takeaways
Community Sentiment
Positives
Concerns

A GitHub Issue Title Compromised 4k Developer Machines
Mar 5, 2026

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
Apr 30, 2026

We May Be Living Through the Most Consequential Hundred Days in Cyber History
Apr 13, 2026

Notepad++ supply chain attack breakdown
Feb 3, 2026

Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
Mar 15, 2026