Blog

Recent
Cloud Security

Axios Compromised: The 2-Hour Window Between Detection and Damage

Hours ago, axios - one of the most popular npm packages with 60M+ weekly downloads - was compromised. Malicious versions dropped a multi-platform RAT with anti-forensic cleanup. This is the second major supply chain attack in a week, days after TeamPCP's Trivy/LiteLLM campaign. The CI/CD scanner side of this story is well-documented. This post is about what happens after the malware runs - because that's where most organizations actually fail.
Petr Zuzanov
Petr Zuzanov
Mar 31
min
All posts
Stream Team
Stream Team
May 18, 2023
min
Stream Team
Stream Team
Apr 18, 2023
min

What's new