Decipher Security Podcast

Axios NPM Supply Chain Attack

March 31 · 25 min · 24.9 MB
0:00-25:41

Streams straight from the publisher. podnod never proxies or re-hosts episode audio.

Dennis and Lindsey dig into what we know do far about the supply chain attack on the axios NPM package, including how the attacker gained access to the maintainer's account, the window of exposure for the malicious packages, the behavior of the RAT that's installed on victims' machines, and what the downstream effects may be.


Links

Huntress post: https://www.huntress.com/blog/supply-chain-compromise-axios-npm-package

Socket analysis: https://socket.dev/blog/axios-npm-package-compromised