An open-source project called Axios (not the website), which has over 100M downloads weekly, was briefly hijacked overnight to drop remote access malware into two releases, potentially affecting countless developers. Already called "one of the most impactful npm supply chain attacks on record." 👀
by the very excellent @carlypage: https://www.theregister.com/2026/03/31/axios_npm_backdoor_rat/






