All updates
Written by Apr 1, 2026

security: Mitigating the Axios npm supply chain compromise

Apr 1, 2026

Microsoft reports that Axios was compromised in a March 31, 2026 npm supply chain attack. Two newly published version-update packages were used to download from command-and-control infrastructure, which Microsoft Threat Intelligence attributes to the North Korean actor Sapphire Sleet.

Sponsored by GitAds