Attack on axios software developer tool threatens widespread compromises

Tim Starks and Derek B Johnson report A hacker briefly delivered malware this week through a popular opensource project for software developers that has an estimated 100 million weekly downloads raising the possibility of compromises spreading widely through a supplychain attack Axios is a JavaScript client library used in web requests The unknown attacker hijacked Source