4 articles and related resources
On March 31, 2026, North Korean hackers compromised the Axios npm package, highlighting critical vulnerabilities in the software supply chain.
On March 31, 2026, the widely-used JavaScript library Axios was compromised in a supply chain attack, leading to the publication of malicious versions containin
The widely-used Axios npm package was compromised in a significant supply chain attack, affecting millions of applications and exposing sensitive data.
The Shai-Hulud worm compromised over 1,000 npm packages, exposing 25,000 GitHub repositories, highlighting critical supply chain security vulnerabilities.
CISA issues an urgent advisory on the Shai-Hulud npm supply chain attack, compromising over 500 packages and urging immediate dependency reviews.