The Axios library was attacked through a supply chain, with hackers using stolen npm tokens to implant a remote trojan, affecting about 80% of cloud environments
The attacker stole the npm access token of the chief maintainer of Axios, the most popular HTTP client library for JavaScript, and used that token to publish two malicious versions containing cross-platform remote access trojans (RATs) (axios@1.14.1 and axios@0.3.4), targeting macOS, Windows, and Linux systems. The malicious packages were removed from the npm registry about 3 hours after being published.
According to data from security company Wiz, Axios is downloaded over 100 million times weekly and exists in about 80% of cloud and code environments. Security company Huntress detected the first infections just 89 seconds after the malicious packages went live and confirmed that at least 135 systems were compromised during the exposure window. Notably, the Axios project had previously deployed modern security measures such as OIDC trusted publishing mechanisms and SLSA provenance proofs, but the attacker completely bypassed these defenses. Investigations revealed that while configuring OIDC, the project retained the traditional long-lived NPM_TOKEN, and npm defaults to using the traditional token when both coexist, allowing the attacker to publish without breaching OIDC.
You may also like

The large models in the United States are moving towards closure in the name of security

Morning Report | CoinEx becomes a key hub for Iran to evade sanctions, involving over $3.8 billion in funds; Kalshi seeks a new round of financing, with a valuation potentially rising to $40 billion

From the white-haired stock god to the billionaire fund mogul, the smart people shorting Nvidia are all getting rich using the same framework

Why do cryptocurrency projects always like to change their names?

Global Launch: As predictions become the most scarce asset in the AI era, Manadia is defining the next generation of the value internet

Who is footing the bill for the $64 billion accounting frenzy?

I never expected that the first application of AI x Crypto would be in security auditing

What is your view on Binance's competitive advantages?

ETH has entered a non-consensus phase, and the turning point is approaching!

The shift in the cloud of the air: from despising stablecoins a year ago to the high-profile entry of capital today

The survival dilemma of small and medium exchanges behind the withdrawal anomalies exposed by AscendEX

Why Is Bitcoin Falling Below $60K? 5 Key Market Drivers Explained
Bitcoin has dropped sharply amid ETF outflows, Strategy stock weakness, AI stock rallies, and changing Fed expectations. Explore the key forces driving BTC’s latest correction and what traders should watch next.

Bitcoin vs. Gold in 2026: Which Asset Performs Better in Different Markets?

Morning News | The draft amendment to the People's Bank of China Law aims to clarify the legal status of digital renminbi; South Korea will transfer about 40 unregistered virtual asset service providers to law enforcement agencies

The cryptocurrency industry has entered the "Show Me" era: merely relying on vision is no longer enough

Interpreting the Ethereum Foundation's new structure: Reaffirming self-sovereignty amid institutional trends

Former SpaceX engineer reconstructs the financial execution system using first principles

