All updates
Written by Apr 1, 2026

security: Mitigating the Axios npm supply chain compromise

Apr 1, 2026

Microsoft reported that Axios was hit by a supply chain attack on March 31, 2026. Malicious npm releases 1.14.1 and 0.30.4 were used to fetch content from a C2 server linked to the North Korean actor Sapphire Sleet; the compromised versions have since been removed.

Sponsored by GitAds