Post Mortem: axios NPM supply chain compromise | Hacker News
TL;DR AI
2 min readKey summary
Maintainers reported an owner account was compromised and a contributor’s machine had a RAT infection.
An attacker published a malicious axios v1 release that lacked OIDC provenance attestations while legitimate v1 releases had them.
Commenters said npm accepted the malicious publish despite missing attestations and urged use of commit/package signing and hardware tokens to prevent impersonation.


