An attacker compromised the npm account of a lead Axios maintainer on March 30, and used it to publish two malicious versions of the widely used JavaScript HTTP client library.
Up to four npm packages on Axios were replaced with malicious versions, in one of the most sophisticated supply chain attacks.