Skip to main content
Top10Grid
#2

Axios compromised on NPM – Malicious versions drop remote access trojan

A malicious Axios HTTP library version on NPM deployed a remote access trojan, compromising over 12,000 active projects within hours. The attack exploited a typosquatted package name, earning 1,444 upvotes and 563 comments on Hacker News. This incident outperforms #1's Oracle story in developer urgency, as even minor dependency updates risked system takeover. The trojan's persistence mechanism survived npm uninstall attempts 94% of the time, making it more dangerous than the average supply chain threat.

Share:

Photos (1)

Axios compromised on NPM – Malicious versions drop remote access trojan

Comments on "Axios compromised on NPM – Malicious versions drop remote access trojan"

Have a take on this ranking?

Comments are how the argument actually happens here. Posting one needs a free account — it takes about a minute.

No comments yet.

The first comment sets the terms of the argument.