Switch language한국어
Back to the list

Post Mortem: axios NPM supply chain compromise | Hacker News

TL;DR AI

Key summary

2 min read
  1. Maintainers reported an owner account was compromised and a contributor’s machine had a RAT infection.

  2. An attacker published a malicious axios v1 release that lacked OIDC provenance attestations while legitimate v1 releases had them.

  3. Commenters said npm accepted the malicious publish despite missing attestations and urged use of commit/package signing and hardware tokens to prevent impersonation.

Read the original