Twelve Trust Boundaries: A Field Guide to Supply-Chain Defense After axios@1.14.1
On March 30, 2026, an attacker who had stolen an axios maintainer's npm publish credentials pushed axios@1.14.1 to the registry. The version looked like a normal patch a single-digit bump from 1.14.0. It was live for roughly three hours before the maintainer rotated credentials and the version was unpublished. Three hours, on a Monday, during peak CI/CD hours across multiple time zones. Any team running pnpm install or npm install against a ^1.14.0 constraint pulled 1.14.1 automatically. (^1.14...
Original Source
Read the full article at Dev →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.