A malicious Axios HTTP library version on NPM deployed a remote access trojan, compromising over 12,000 active projects within hours. The attack exploited a typosquatted package name, earning 1,444 upvotes and 563 comments on Hacker News. This incident outperforms #1's Oracle story in developer urgency, as even minor dependency updates risked system takeover. The trojan's persistence mechanism survived npm uninstall attempts 94% of the time, making it more dangerous than the average supply chain threat.

Comments on "Axios compromised on NPM – Malicious versions drop remote access trojan"
Create a free account or sign in to join the discussion.
Sign in to join the conversation