Switch language한국어
Back to the list

Supply chain attack hits popular library Axios, downloaded over 100 million times; it started with a sophisticated account takeover: In security circles lately

TL;DR AI

Key summary

2 min read
  1. Axios was hit by a supply-chain attack after a maintainer was socially engineered and had credentials stolen.

  2. Fake Axios 1.14.1 and 0.30.4 packages were published to npm with malicious dependencies designed to install remote-access malware on macOS, Windows, and Linux.

  3. The tainted packages were removed after about three hours, but Microsoft and Google linked the activity to the North Korea–aligned Sapphire Sleet group.

  4. Because Axios is downloaded more than 100 million times a week, the incident could have spread widely across developer and production environments.

Read the original