YC Lian π²πΎπΈπ¬
@yclian
Techie at @ServiceRocket; ex @OnApp @Aflexi CDN, @SinarProject;
ID: 14964173
https://linkedin.com/in/yclian/ 31-05-2008 16:08:34
6,6K Tweet
407 Followers
99 Following
π¨ CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios
Socket UPDATE in case you missed it earlier: This is bigger than initially reported. Both [email protected] AND [email protected] were compromised β the attacker poisoned the 1.x and 0.x branches within 39 minutes of each other, maximizing blast radius across projects using caret ranges.