Hacker hijacks Axios open-source project, used by millions, to push malware

TL;DR AI
2 min readKey summary
A hacker compromised a primary developer account and pushed malicious versions of the Axios library to npm.
The malicious updates delivered a remote access trojan and were published as legitimate-looking updates for Windows, macOS, and Linux.
Security firm StepSecurity said the hijack lasted about three hours before being stopped, and Aikido advised downloaders to assume compromise.



