Axios npm Supply Chain Attack: What Happened, How to Check, and What It Means
One compromised npm token. 174,000 dependent projects. A RAT in 1.1 seconds. Malicious axios versions 1.14.1 and 0.30.4 dropped a self-deleting trojan via a hidden plain-crypto dependency. QSL ran full detection on our EC2 immediately — here's the breakdown, IoCs, detection commands, and HIPAA implications.
Read Full Analysis