Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
Researchers say they’ve discovered a supply-chain attack flooding repositories with malicious packages that contain invisible ...
Security teams are grappling with a major supply chain attack on Axios, a popular JavaScript library with over 100 million ...
ThreatDown, the corporate business unit of Malwarebytes, today published research documenting what researchers believe to be ...
Maintainer Jordan Harband writes on Bluesky that attackers had taken over the account of another project manager. Versions 3.3.1 and 5.0.0 of the package are affected. Both versions were apparently ...
一部の結果でアクセス不可の可能性があるため、非表示になっています。
アクセス不可の結果を表示する