Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
GlassWorm uses a fake WakaTime VS Code extension to infect IDEs, deploy RATs, and steal data, prompting urgent credential ...
A widely used JavaScript package used with hundreds of millions of downloads has been compromised in a new supply chain ...
A convincing Microsoft lookalike tricks users into downloading malware that steals passwords, payments, and account access.
The widely used Axios HTTP client library, a JavaScript component used by developers, was recently hacked to distribute ...
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
"To understand how private company leaders are positioning their businesses for that moment, we asked 100 executives about their upcoming timing, priorities, and pressure points." ...
Security teams are grappling with a major supply chain attack on Axios, a popular JavaScript library with over 100 million ...
Apple today released a new update for Safari Technology Preview, the experimental browser that was first introduced in March ...
Today, much of our nation’s health care spending still focuses on treating illness instead of preventing it. Employers have ...
UNC1069 compromised Axios 1.14.1 and 0.30.4 via social engineering, impacting 100M weekly downloads and exposing supply ...
Attackers stole a long-lived npm token from the lead axios maintainer and published two poisoned versions that drop a ...