No Result
View All Result
  • Login
Tuesday, March 31, 2026
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Cryptocurrency

Axios NPM Package Compromised in Supply Chain Attack

by FeeOnlyNews.com
3 hours ago
in Cryptocurrency
Reading Time: 2 mins read
A A
0
Axios NPM Package Compromised in Supply Chain Attack
Share on FacebookShare on TwitterShare on LInkedIn



Two malicious Axios npm releases have prompted warnings for developers to rotate credentials and treat affected systems as compromised after a supply chain attack poisoned the popular JavaScript HTTP client library.

The compromise was first reported by cybersecurity company Socket, which said [email protected] and [email protected] were modified to pull in [email protected], a malicious dependency that ran automatically during installation before the releases were removed from npm.

According to security company OX Security, the altered code can give attackers remote access to infected devices, allowing them to steal sensitive data such as login credentials, API keys and crypto wallet information.

The incident shows how a single compromised open-source component can potentially ripple across thousands of applications that rely on it, exposing not just developers but also platforms and users connected to the system. 

Security companies urge key rotation, system audits

OX Security warned developers who installed [email protected] or [email protected] to treat their systems as fully compromised and immediately rotate credentials, including API keys and session tokens.

Socket said the compromised Axios releases were modified to include a dependency on [email protected], a package published shortly before the incident and later identified as malicious.

Related: Trust Wallet browser extension knocked offline by Chrome Store ‘bug,’ CEO says

The company said the dependency was configured to run automatically during installation through a post-install script, allowing attackers to execute code on target systems without additional user interaction.

Socket advised developers to review their projects and dependency files for the affected Axios versions and the associated [email protected] package, and to remove or roll back any compromised versions immediately.

Earlier crypto incidents highlight supply chain risks

Earlier crypto incidents have shown how supply chain breaches can escalate from stolen developer information to user-facing wallet losses.

On Jan. 3, onchain investigator ZachXBT reported that “hundreds” of wallets across Ethereum Virtual Machine-compatible networks were drained in a broad attack that siphoned small amounts from each victim. 

Cybersecurity researcher Vladimir S. said the incident was potentially linked to a December breach affecting Trust Wallet, which resulted in roughly $7 million in losses across over 2,500 wallets. 

Trust Wallet later said the breach may have originated from a supply chain compromise involving npm packages used in its development workflow.

Magazine: Nobody knows if quantum secure cryptography will even work

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy



Source link

Tags: AttackAxiosChaincompromisedNPMPackageSupply
ShareTweetShare
Previous Post

Walter Williams Against Erasing Confederate History

Next Post

10 Surprising Ways Life Gets Better With Age

Related Posts

Hoskinson Slams Ripple Over Crypto Competition Push

Hoskinson Slams Ripple Over Crypto Competition Push

by FeeOnlyNews.com
March 30, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Cardano founder Charles Hoskinson used a lengthy...

Iran Speaker predicts pre-market “reverse indicator” then Bitcoin climbed before the S&P500

Iran Speaker predicts pre-market “reverse indicator” then Bitcoin climbed before the S&P500

by FeeOnlyNews.com
March 30, 2026
0

Mohammad Bagher Ghalibaf, the speaker of Iran’s parliament, posted a striking piece of market commentary on X before the latest...

U.S. Senate Introduces ‘Mined in America’ Act Backing Strategic Bitcoin Reserve

U.S. Senate Introduces ‘Mined in America’ Act Backing Strategic Bitcoin Reserve

by FeeOnlyNews.com
March 30, 2026
0

U.S. Senators Bill Cassidy and Cynthia Lummis have introduced the Mined in America Act, which aims to codify U.S. President...

Meta tests Instagram Plus subscription with stealth story viewing and paid features for users

Meta tests Instagram Plus subscription with stealth story viewing and paid features for users

by FeeOnlyNews.com
March 30, 2026
0

Meta Platforms has begun testing a new premium subscription called Instagram Plus, offering everyday users access to exclusive features as...

Ripple CEO Talked About A  Trillion Opportunity, But Will XRP Investors Benefit From It?

Ripple CEO Talked About A $13 Trillion Opportunity, But Will XRP Investors Benefit From It?

by FeeOnlyNews.com
March 30, 2026
0

Ripple CEO Brad Garlinghouse has revealed a $13 trillion opportunity, which cryptos like XRP and stablecoins could tap into. This...

Pro-AI Group to Spend 0 Million on United States Midterm Elections – News Bytes Bitcoin News

Pro-AI Group to Spend $100 Million on United States Midterm Elections – News Bytes Bitcoin News

by FeeOnlyNews.com
March 30, 2026
0

Innovation Council Action (ICA) announces a $100 million spending plan targeting the November 8 US midterm elections to back candidates...

Next Post
10 Surprising Ways Life Gets Better With Age

10 Surprising Ways Life Gets Better With Age

Linde (LIN): Gase-Riese vor frischen Kaufsignal!

Linde (LIN): Gase-Riese vor frischen Kaufsignal!

  • Trending
  • Comments
  • Latest
Judge orders SEC to release data behind B in WhatsApp fines

Judge orders SEC to release data behind $2B in WhatsApp fines

March 10, 2026
8 Cost-Cutting Moves Retirees Are Sharing Online in February

8 Cost-Cutting Moves Retirees Are Sharing Online in February

February 14, 2026
The 23 Largest Global Startup Funding Rounds of February 2026 – AlleyWatch

The 23 Largest Global Startup Funding Rounds of February 2026 – AlleyWatch

March 27, 2026
Easter Basket Ideas for Kids

Easter Basket Ideas for Kids

March 23, 2026
3 Grocery Chains That Give Seniors a “Gas Bonus” for Every  Spent

3 Grocery Chains That Give Seniors a “Gas Bonus” for Every $50 Spent

March 15, 2026
8 Procedures That Can Be Cheaper Without Insurance

8 Procedures That Can Be Cheaper Without Insurance

February 14, 2026
Mine appoints senior privacy executive

Mine appoints senior privacy executive

0
Warren Buffett says he’s still making calls on investments at Berkshire, flags ‘tiny’ new buy

Warren Buffett says he’s still making calls on investments at Berkshire, flags ‘tiny’ new buy

0
Rotate your European portfolio to prepare for stagflation risk, Goldman Sachs says

Rotate your European portfolio to prepare for stagflation risk, Goldman Sachs says

0
Warren Buffett says he sold Apple too soon and would buy more of it, though not in this market

Warren Buffett says he sold Apple too soon and would buy more of it, though not in this market

0
Ben & Jerry’s: Free Cone Day on April 14th!

Ben & Jerry’s: Free Cone Day on April 14th!

0
Nobody prepares you for the hardest lesson of your 50s – that some of the people you sacrificed for genuinely don’t remember what you gave up, and it’s not cruelty, it’s just the way memory works when you were never the main character in their story

Nobody prepares you for the hardest lesson of your 50s – that some of the people you sacrificed for genuinely don’t remember what you gave up, and it’s not cruelty, it’s just the way memory works when you were never the main character in their story

0
Mine appoints senior privacy executive

Mine appoints senior privacy executive

March 31, 2026
Warren Buffett says he’s still making calls on investments at Berkshire, flags ‘tiny’ new buy

Warren Buffett says he’s still making calls on investments at Berkshire, flags ‘tiny’ new buy

March 31, 2026
Warren Buffett says he sold Apple too soon and would buy more of it, though not in this market

Warren Buffett says he sold Apple too soon and would buy more of it, though not in this market

March 31, 2026
Ben & Jerry’s: Free Cone Day on April 14th!

Ben & Jerry’s: Free Cone Day on April 14th!

March 31, 2026
Rotate your European portfolio to prepare for stagflation risk, Goldman Sachs says

Rotate your European portfolio to prepare for stagflation risk, Goldman Sachs says

March 31, 2026
Nobody prepares you for the hardest lesson of your 50s – that some of the people you sacrificed for genuinely don’t remember what you gave up, and it’s not cruelty, it’s just the way memory works when you were never the main character in their story

Nobody prepares you for the hardest lesson of your 50s – that some of the people you sacrificed for genuinely don’t remember what you gave up, and it’s not cruelty, it’s just the way memory works when you were never the main character in their story

March 31, 2026
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Mine appoints senior privacy executive
  • Warren Buffett says he’s still making calls on investments at Berkshire, flags ‘tiny’ new buy
  • Warren Buffett says he sold Apple too soon and would buy more of it, though not in this market
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.