- 31st March 2026
One of the most widely used npm packages — axios — was compromised via a hijacked maintainer account on March 31, 2026. Versions 1.14.1 and 0.30.4 contain a hidden dependency that deploys a cross-platform remote access trojan in under 15 seconds. No CVE assigned. Traditional scanners will not catch it.
Francesco Cipollone