Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
A North Korea-nexus threat actor compromised the widely used axios npm package, delivering a cross-platform remote access ...
LangChain and LangGraph have patched three high-severity and critical bugs.
With almost 175,000 npm projects listing the library as a dependency, the attack had a huge cascade effect and shows how ...
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
Four vulnerabilities in CrewAI could be chained together via prompt injection for sandbox escape, remote code execution, and ...
North Korean hackers published backdoored versions of the Axios NPM package using a compromised long-lived access token.