On March 31, 2026, one of the most operationally sophisticated supply chain attacks ever documented hit axios — an npm package with 83 million weekly downloads and adoption across virtually every JavaScript ecosystem.
An attacker compromised the npm credentials of jasonsaayman, the lead maintainer of axios. The attacker:
