Kompromittierte axios npm-Pakete verbreiten Schadsoftware

CERT.at Version 1 original current

Imported from official source

Die weit verbreitete JavaScript-Bibliothek axios (HTTP-Client mit über 300 Millionen wöchentlichen Downloads auf npm) wurde durch kompromittierte Paketversionen als Angriffsvektor missbraucht. Über den gekaperten npm-Account eines Hauptentwicklers wurden zwei schadhafte Versionen veröffentlicht: [email protected] und [email protected]. …

This version

Version
1 of 1
Recorded
October 03, 2026 20:37
Change
Initial
Content hash
0b05ac3706481a0320d486942871b445
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.