Axios Was Hijacked for Two Hours. npm's Trust Architecture Made It Inevitable.
technical
7 min read

Axios Was Hijacked for Two Hours. npm's Trust Architecture Made It Inevitable.

The Axios supply chain attack deployed a cross-platform RAT to millions of machines. The real vulnerability isn't the stolen token; it's npm's authentication model.