Skip to content
Dev.to1 min read

Someone Backdoored axios on npm. Here is How to...

On March 31, 2026, two malicious versions of axios were published to npm: axios@1.14.1 and axios@0.30.4. Both were live for roughly three hours before npm pulled them down. During that window, anyone who ran npm install axios could have had a Remote Access Trojan (RAT) dropped silently on their machine or CI runner, with no errors and no warnings. This post breaks down what happened, how the attack worked, and the exact commands to check if you were affected. What happened The attacker compromis
Read original on dev.to
0
0

Comment

Sign in to join the discussion.

Loading comments…

Related

Get the 10 best reads every Sunday

Curated by AI, voted by readers. Free forever.

Liked this? Start your own feed.

0
0