Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Axios npm Supply Chain Attack: Emergency Detection and Incident Response for Malicious Versions 1.14.1 and 0.30.4
Introduction A confirmed supply chain attack has compromised the Axios npm package, one of the most widely used HTTP client libraries in the...
Axios npm Supply Chain Compromise: Detection & Remediation for Versions 1.14.1 and 0.30.4
Introduction On March 31, 2026, the JavaScript ecosystem faced a critical supply chain assault. The Cybersecurity and Infrastructure Securit...
NPM Supply Chain Attack: Malicious Axios Versions (1.6.0-1.6.2) Detection and Remediation
Introduction The open-source ecosystem suffered a significant trust breach when the popular HTTP client library Axios was compromised. Threa...
Axios npm Supply Chain Attack: Detection and Incident Response for Versions 1.14.1 and 0.30.4
Introduction The widely popular HTTP client Axios has been confirmed compromised in a critical supply chain attack. Malicious versions 1.14....
OpenAI macOS Certificate Revocation: Axios Supply Chain Incident and Hardening
OpenAI macOS Certificate Revocation: Axios Supply Chain Incident and Hardening Introduction On March 31, 2026, OpenAI disclosed a significan...
UNC1069 Axios npm Compromise: Supply Chain Detection and Defense
UNC1069 Axios npm Compromise: Supply Chain Detection and Defense Introduction The open-source ecosystem is currently facing a critical secur...
Axios npm Supply Chain Attack (UNC1069): Detecting WAVESHAPER.V2 and Remediation for Versions 1.14.1/0.30.4
On March 31, the open-source ecosystem suffered a significant shock when the widely used axios npm package—boasting over 100 million weekly ...
Axios npm Supply Chain Attack: Detection and Removal of Cross-Platform RAT (v1.14.1 & v0.30.4)
Axios npm Supply Chain Attack: Detection and Removal of Cross-Platform RAT (v1.14.1 & v0.30.4) Introduction The Axios npm package, a ubiquit...
Axios NPM Supply Chain Compromise: Detecting Industrialized Social Engineering and Malicious Packages
Introduction The recent attack on the axios NPM package is a wake-up call for the software development lifecycle. Threat actors have moved b...