axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity

Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT. We are actively investigating and will update this post with a full technical analysis.

@xgebi dependabot lets you set a minimum age of a dependency before a PR is raised, something like 7+ days old apparently protects against these attacks affecting you -by then it's already surfaced and the malware blocker will be at work.

Key: never be in a rush to update your NPM dependencies. If you must use NPM
#cybersecurity