Axios npm hack used fake Teams error fix to hijack maintainer account

The maintainers of the popular Axios HTTP client have published a detailed post-mortem describing how one of its developers was targeted by a social engineering campaign believed to have been conducted by North Korean threat actors.

BleepingComputer

@ai6yr " ...tried to get me to run a curl command that would download and run something, then when I refused they went dark and deleted all conversations,"

Yeah, that must have been an a-ha moment (not an o crap one).