The TeamPCP hacking group has hacked the Telnyx PyPI package as part of a supply chain campaign targeting the broad OSS ecosystem.
A critical supply chain attack has compromised the popular JavaScript library axios, leading to developers unknowingly ...
Strapi plugins exploit Redis and PostgreSQL via postinstall scripts, enabling persistent access and data theft.
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
I keep reaching for my phone, and it’s not for scrolling.
The widely used Axios HTTP client library, a JavaScript component used by developers, was recently hacked to distribute ...
Two versions of the widely used JavaScript library axios were maliciously published on npm on March 31, 2026. A hijacked ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
Axios 1.14.1 and 0.30.4 injected malicious [email protected] after npm compromise on March 31, 2026, deploying ...
The TeamPCP hacking group has been using credentials stolen in the recent OSS campaign to enumerate and compromise AWS ...
With almost 175,000 npm projects listing the library as a dependency, the attack had a huge cascade effect and shows how ...
TeamPCP strikes again, with almost identical code to LiteLLM.