Switch language한국어
Back to the list

Hacker hijacks Axios open-source project, used by millions, to push malware

TL;DR AI

Key summary

2 min read
  1. A hacker compromised a primary developer account and pushed malicious versions of the Axios library to npm.

  2. The malicious updates delivered a remote access trojan and were published as legitimate-looking updates for Windows, macOS, and Linux.

  3. Security firm StepSecurity said the hijack lasted about three hours before being stopped, and Aikido advised downloaders to assume compromise.

Read the original