I'm not giving in to the vibes yet.
An attacker compromised the npm account of a lead Axios maintainer on March 30, and used it to publish two malicious versions ...