The compromise of Axios is another reminder to configure your package manager to use a minimum release age. Not a perfect solution but provides folks a few days to catch and respond to a supply chain attack.
axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity
Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT. We are actively investigatin...
stepsecurity.io