Skip to content
Dev.to1 min read

Post-Mortem: The March 2026 Axios Supply Chain...

The Incident On March 31, 2026, a high-profile supply chain attack targeted Axios, a critical HTTP client for the JavaScript ecosystem. By hijacking a maintainer's NPM account, attackers injected a malicious dependency, plain-crypto-js, which deployed a cross-platform Remote Access Trojan (RAT). Incident Summary Detail Information Affected Versions axios@1.14.1, axios@0.30.4 Malicious Dependency plain-crypto-js@4.2.1 Payload Cross-platform RAT (Linux, macOS, Windows) C2 Server sfrclak.com:8000 R
Read original on dev.to
0
0

Comment

Sign in to join the discussion.

Loading comments…

Related

Get the 10 best reads every Sunday

Curated by AI, voted by readers. Free forever.

Liked this? Start your own feed.

0
0