On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
The popular JavaScript HTTP client Axios has been compromised in a supply chain attack, exposing projects to malware through ...
A North Korea-nexus threat actor compromised the widely used axios npm package, delivering a cross-platform remote access ...
Researchers say they’ve discovered a supply-chain attack flooding repositories with malicious packages that contain invisible ...
The bug was assigned CVE-2025-2135, and we successfully used it to pwn Google’s V8CTF as a zero-day. The root cause lies in TurboFan’s InferMapsUnsafe() function, which fails to handle aliasing when ...
Chainguard is racing to fix trust in AI-built software - here's how ...
If your e-mail ends in Yahoo, Hotmail or Sympatico.ca, I see you. We were early adopters. And now, if we’re still clinging to ...
The connection between institutional memory and civilizational decline is not metaphorical – the library of Alexandria has ...
This is GlassWorm: a software supply chain attack that security researchers are calling one of the most sophisticated and ...
Cybercriminals are increasingly prioritizing speed and scalability over technical sophistication. Rather than crafting highly ...