Blog

Recent
Cloud Security

Axios Compromised: The 2-Hour Window Between Detection and Damage

Hours ago, axios - one of the most popular npm packages with 60M+ weekly downloads - was compromised. Malicious versions dropped a multi-platform RAT with anti-forensic cleanup. This is the second major supply chain attack in a week, days after TeamPCP's Trivy/LiteLLM campaign. The CI/CD scanner side of this story is well-documented. This post is about what happens after the malware runs - because that's where most organizations actually fail.
Petr Zuzanov
Petr Zuzanov
Mar 31
min
All posts

What's new