Patrick Tech Co. VN

Hacker hijacks Axios open-source project, used by millions, to push malware

A hacker has hijacked and modified a popular open-source software development tool to deliver malware that could put millions of developers at risk of being compromised.

Emerging The topic has initial corroboration, but the newsroom is still waiting on stronger confirmation.
Reference image for: Hacker hijacks Axios open-source project, used by millions, to push malware
Reference image from TechCrunch. TechCrunch

A hacker has hijacked and modified a popular open-source software development tool to deliver malware that could put millions of developers at risk of being compromised. On Monday, a hacker pushed malicious versions of the widely used JavaScript library called Axios, which developers rely on to allow their software to connect to the internet.

Advertising slot

Reserved for Google AdSense

What happened

A hacker has hijacked and modified a popular open-source software development tool to deliver malware that could put millions of developers at risk of being compromised.

Why it matters

On Monday, a hacker pushed malicious versions of the widely used JavaScript library called Axios, which developers rely on to allow their software to connect to the internet. The affected library was hosted on npm , a software repository that stores code for open-source projects. Axios is downloaded tens of millions of times every week.

Advertising slot

Reserved for Google AdSense

What to watch next

The hijack was spotted and stopped in around three hours overnight on Monday into Tuesday, according to security firm StepSecurity, which analyzed the attack .

Source notes

From Patrick Tech

Contextual tools

Related stories