Malicious Axios npm Packages Trigger Supply Chain Security Alert for Developers
-

Two compromised versions of the popular JavaScript library Axios have raised serious security concerns after being found to include a malicious dependency. The affected releases automatically executed harmful code during installation, potentially giving attackers remote access to developer systems.
Security experts are urging immediate action, warning that any system using these versions should be treated as compromised. Developers are advised to rotate credentials, remove affected packages, and audit their systems to prevent further damage.