lazarusholic

Everyday is lazarus.dayβ

axios Compromised: npm Supply Chain Attack via Dependency Injection

2026-03-31, SafeDep
https://safedep.io/axios-npm-supply-chain-compromise/
#Axios #NPM

Contents

Compromised telnyx on PyPI: WAV Steganography and Credential Theft
Analysis of malicious telnyx 4.87.1 and 4.87.2 on PyPI — a package with over 1 million monthly downloads: injected code uses WAV audio steganography to deliver payloads that steal credentials and...