Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
The full breadth of this incident is still unclear, but given the popularity of the compromised package, we expect it will ...