Axios functions as pre-built software that a developer can easily incorporate into a JavaScript project. However, a hacker ...
North Korean hackers published backdoored versions of the Axios NPM package using a compromised long-lived access token.
The NPM package for Axios, a popular JavaScript HTTP client library, was briefly compromised this week, possibly by North ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
Malware in open source software is no longer a fringe threat--it's accelerating at an unprecedented rate. In 2025 alone, more than ...
VANCOUVER, British Columbia--(BUSINESS WIRE)--Today at Node.js Interactive North America, npm, Inc., which runs the world’s largest software registry and maintains the npm software package management ...
A new malicious npm campaign using fake installation logs to hide malware activity has been identified by security ...
Four packages containing highly obfuscated malicious Python and JavaScript code were discovered this week in the Node Package Manager (npm) repository. According to a report from Kaspersky, the ...
OAKLAND, Calif.--(BUSINESS WIRE)--npm, Inc., which runs the world’s largest software registry and maintains the `npm` software development tool, today announced that the npm Registry has achieved one ...
A new set of 16 malicious NPM packages are pretending to be internet speed testers but are, in reality, coinminers that hijack the compromised computer's resources to mine cryptocurrency for the ...
Researchers continue to investigate a wave of malicious npm packages, with the published tally now reaching over 700. Last week, JFrog researchers disclosed the scheme in which an unknown threat actor ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results