Axios npm Supply Chain Attack: How Install-Time Malware Compromised Millions of JavaScript Projects
On March 31, 2026, a malicious update to the Axios npm package transformed one of JavaScript's most trusted HTTP clients into a weaponized supply chain threat. The attack didn't require developers to...