A North Korea-linked threat actor (UNC1069) hijacked the npm account of an axios maintainer and published two backdoored versions. They were live for ~3 hours before npm removed them.
- 00:21 — Malicious
axios@1.14.1published (latest dist-tag) - 00:39 — Malicious
axios@0.30.4published (legacy dist-tag) - ~03:15 — npm removes compromised versions