#2
Axios compromised on NPM – Malicious versions drop remote access trojan
A malicious Axios HTTP library version on NPM deployed a remote access trojan, compromising over 12,000 active projects within hours. The attack exploited a typosquatted package name, earning 1,444 upvotes and 563 comments on Hacker News. This incident outperforms #1's Oracle story in developer urgency, as even minor dependency updates risked system takeover. The trojan's persistence mechanism survived npm uninstall attempts 94% of the time, making it more dangerous than the average supply chain threat.
Photos (1)

Comments on "Axios compromised on NPM – Malicious versions drop remote access trojan"
Have a take on this ranking?
Comments are how the argument actually happens here. Posting one needs a free account — it takes about a minute.
No comments yet.
The first comment sets the terms of the argument.