Supply Chain
The Axios Supply Chain Attack: How North Korea Hijacked npm's Most Popular HTTP Client
For two hours on March 31, anyone who ran npm install axios got a North Korean RAT. The real package, the real registry, the real maintainer account — compromised.