NEW: Someone hijacked an open-source software development tool to push malware to millions of people.

The supply chain attack was stopped in less than three hours, but it's still unclear how many people got hacked.

https://techcrunch.com/2026/03/31/hacker-hijacks-axios-open-source-project-used-by-millions-to-push-malware/

North Korean hackers blamed for hijacking popular Axios open source project to spread malware | TechCrunch

A hacker inserted malware in Axios, an open source web tool downloaded tens of millions of times weekly, in a widespread hack.

TechCrunch

@lorenzofb

This malware is fully multiplatform, so it works in Windows, MacOS and LInux. And more.

Yuck.