Socket: The npm package axios has been compromised in a supply chain attack. The latest version 1.14.1 has been injected with malicious code.

robot
Abstract generation in progress

ME News message, March 31 (UTC+8), SlowMist founder Yu Xuan reposted an alert by Socket AI founder Feross, saying that the npm ecosystem’s core dependency package axios is under an active supply-chain attack. Its latest version, axios@1.14.1, has been injected with a malicious package plain-crypto-js@4.2.1 that previously had never existed. Socket AI’s analysis has confirmed that this package is malware. axios has more than 100 million weekly downloads, and all projects that pull the latest versions face a potential compromise risk. Feross urged all axios users to immediately lock their versions and review their lock files, and not to upgrade to the latest version. (Source: Foresight News)

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin