Today, March 31, 2026, the popular npm package axios was compromised via a compromised maintainer account. Malicious versions were released that install a Remote Access Trojan (RAT).
The malware hides in a new dependency called [email protected]. This executes a postinstall-Script that immediately attempts to steal secrets (keys, .env, SSH).
Interesting Videos for this Supply Chain Attack on Youtube:
From NetworkChuck - A Git hosted Guide for Checks!
https://github.com/theNetworkChuck/axios-attack-guide
Stay Safe Guys!