npm core dependency package axios version 1.14.1 was compromised in a supply-chain attack and had malicious code injected

Gate News message, March 31, Socket AI issued a security alert. npm ecosystem core dependency package axios has been targeted by an active supply-chain attack. Its latest version, axios@1.14.1, was injected with a malicious package plain-crypto-js@4.2.1 that had never existed before. Socket AI’s analysis has confirmed that this package is malware. axios has more than 100 million weekly downloads, and all projects pulling the latest version face a potential compromise risk. Socket AI founder Feross advises all axios users to immediately lock their version and review the lockfile, and not upgrade to the latest version.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
No comments