home.social

#axios — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #axios, aggregated by home.social.

  1. v1.16.1

    v1.16.1 — May 13, 2026 This release ships a defence-in-depth fix for prototype pollution in formDataToJSON, hardens proxy and CI workflows, restores Webpack 4 compatibility for the fetch adapter, and includes several small bug fixes and maintenance...

    github.com/axios/axios/release

    #axios #nodejs

  2. @himay

    It's bullshit. Its just a fucking #OpenAI prompt to drum up manufactured news.

    "Why it matters: As the pastor role becomes lower-paid, higher-risk and less trusted, the U.S. isn't just losing clergy — it's losing a key layer of local leadership, especially in rural and Black communities."

    (bullshit) (COLON) (uncited claim)

    FUCKING EMDASH, 5 of these lil fuckers in the article.

    (final prepositional clause, cause OpenAI loves runons)

    I dont care if this is #axios This is #pig #aislop

  3. Will Israel’s use of Iron Dome to aid Arab neighbour recalibrate Mideast defence?

    Israel’s reported deployment of its Iron Dome missile defence battery in the UAE signals a “watershed moment” in…
    #Conflict #Conflicts #War #abrahamaccords #Axios #China #Gulf #hudsoninstitute #Iran #irondome #Israel #LiselotteOdgaard #middleeast #middleeastcrisis #MohamedbinZayed #Russia #S.RajaratnamSchoolofInternationalStudies #unitedarabemirates #US
    europesays.com/2953154/

  4. Will Israel’s use of Iron Dome to aid Arab neighbour recalibrate Mideast defence?

    Israel’s reported deployment of its Iron Dome missile defence battery in the UAE signals a “watershed moment” in…
    #NewsBeep #News #BreakingNews #AbrahamAccords #Axios #breakingnews #China #Gulf #hudsoninstitute #Iran #IronDome #Israel #LiselotteOdgaard #MiddleEast #MohamedBinZayed #Russia #S.RajaratnamSchoolofInternationalStudies #UnitedArabEmirates #Us
    newsbeep.com/509892/

  5. #Axios compromis : l’impact d’une intrusion #nord-coréenne sur la chaîne logistique L’ #attaquant a pris le contrôle du compte du mainteneur, Jason #Saayman, pour publier des versions infectées en contournant les pipelines d’ #intégration #continue #GitHub. www.lemagit.fr/actualites/3...

    Axios compromis : l’impact d’u...

  6. #Axios compromis : l’impact d’une intrusion #nord-coréenne sur la chaîne logistique L’ #attaquant a pris le contrôle du compte du mainteneur, Jason #Saayman, pour publier des versions infectées en contournant les pipelines d’ #intégration #continue #GitHub. www.lemagit.fr/actualites/3...

    Axios compromis : l’impact d’u...

  7. Recent software supply chain attacks - yowers!

    In March, popular open source tools Trivy and Axios were compromised with malware, and we won't know the full blast radius for months.

    Axios was breached by North Korean hackers who turned it into a malware delivery vehicle for about three hours after attackers hijacked a maintainer's account and slipped a remote-access trojan (RAT) into two seemingly legitimate releases.

    Trivy was hacked by a loosely knit band of hackers called TeamPCP, who injected credential-stealing malware.

    "Attackers are starting to really look at the supply chain and open source packages, and figure out ways to compromise developers to deliver malware or gather data" ... theregister.com/2026/04/11/tri #Hackers #Malware #Software #OpenSource #SoftwareSupplyChain #Trojan #CyberSecurity #Security #Trivy #Axios

  8. 🔖 The latest issue of my is live, issue 013.

    March recap: 12 CVEs across , , & , a state-actor supply chain attack on , and the security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  9. 🔖 The latest issue of my #newsletter is live, issue 013.

    March recap: 12 CVEs across #undici, #Fastify, #Lodash & #pathtoregexp, a state-actor supply chain attack on #axios, and the #Nodejs security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  10. 🔖 The latest issue of my #newsletter is live, issue 013.

    March recap: 12 CVEs across #undici, #Fastify, #Lodash & #pathtoregexp, a state-actor supply chain attack on #axios, and the #Nodejs security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  11. 🔖 The latest issue of my #newsletter is live, issue 013.

    March recap: 12 CVEs across #undici, #Fastify, #Lodash & #pathtoregexp, a state-actor supply chain attack on #axios, and the #Nodejs security bug bounty paused 🔐

    blog.ulisesgascon.com/newslett

  12. THREAT MODEL: CYBERSECURITY 🧑‍💻
    for Apr. 7th, 2026
    by independent journalist @violetblue

    - "CEO Said A Thing!" journalism

    - The Medici grand ducal treasure is under cyberattack

    - No one told #Netflix you can’t cheat at chess with a hacked buttplug

    - #Hegseth reduces yearly #USArmy mandatory cybersecurity training to once every five years

    - Trump to cut #CISA funding again

    - More info on the #Axios supply chain breach

    - Circumventing #Russia ’s #Telegram comms ban with a WiFi cat feeder

    - Reconstructing how Audre Lorde’s "The Master's Tools" relates to #Enshittification

    ...and much more.

    ✨THREAT MODEL is free to read -- please help keep it accessible to all by becoming a patron, even $1 a month makes a difference!✨

    patreon.com/posts/cybersecurit

    #ThreatModel #ThreatModelCybersecurity #ThreatModelNewsletters #VioletBlue #infosec #cybersec #CovidIsNotOver

  13. North Korea-linked actor compromises axios NPM package

    A shocking discovery by Google Threat Intelligence Group has exposed a vulnerability in the popular axios NPM package, which has over 100 million weekly downloads, and has raised urgent questions about the trustworthiness of software supply chains. A malicious dependency was secretly introduced into axios releases, putting countless…

    osintsights.com/north-korea-li

    #Axios #Npm #NodePackageManager #NorthKorea #GoogleThreatIntelligenceGroup

  14. Как DNS-фильтрация защитила от компрометации axios в реальном кейсе

    31 марта 2026 года один из самых популярных npm-пакетов в мире превратился в оружие. Разбираем, как устроена атака на цепочку поставок через axios, почему классические средства защиты могут не выручить на этапе заражения – и как DNS-уровень оказался барьером, который предотвратил крупнейший инцидент. Мгновенная атака Представьте, что вы едите в отель. Одну из больших сетевых - из более чем 5000 отелей по всему миру. Устали после пересадки и с единственной мыслью в голове - как можно скорее добраться до номера и открыть ноутбук, доделать задачи к утреннему релизу. Все еще хорошо – информационная система сети отелей работает исправно, заселяя больше 500 гостей в минуту. Вы открываете дверь такси и выходите. До стойки ресепшн рукой подать, идти чуть больше минуты - 89 секунд. Но дойдя до нее вы видите, как меняется лицо администратора. Глядя в экран, она видит сообщение о сбое всех систем. Именно столько – 89 секунд прошло между публикацией вредоносной версии axios и первым заражением. Горизонтальное же продвижение злоумышленников, вооруженных мощью автономных AI-агентов может быть мгновенным. Получив доступ к переменным окружения, токенам CI/CD, ключам доступа к облакам, БД, API платёжных шлюзов, секретам Kubernetes с компьютеров разработчиков – дальнейшее дело техники. И это реальное описание того, что могло бы случиться, если бы клиент не использовал сервис DNS-фильтрации.

    habr.com/ru/companies/ideco/ar

    #Ideco #ngfw #dns #атаки #информационная_безопасность #axios #кейс

  15. The maintainer of Axios has come forward on how they got phised by NK in the Supply-chain attack.

    Many people said "hurr duurr, look at the link! how on earth you gonna fell for that?!", ignoring the setup:
    - Pretend to be a legitimate tech founder
    - A look like real Slack Workspace

    When you got a false sense of legitimacy, they can toy you on whatever they wanted you to do.

    #cybersecurity #infosec #security #axios #supplychainattack

  16. Nachdem es in den letzten Jahren Angriffe auf #Solarwinds oder #Kaseya gab, steht immer stärker auch die #Opensource Community im Fokus von #Cybercrime, indem durch die Kompromittierung einer Maintainer-Identität potenziell Millionen von Entwicklungsumgebungen und CI/CD-Pipelines ebenfalls kompromittiert werden.

    So haben haben Angreifer die #JavaScript-Bibliothek #Axios, eine der meistgenutzten Komponenten moderner Webentwicklung, zeitweise mit #Schadsoftware bestückt:

    it-daily.net/shortnews/npm-bib

  17. Naty @eclecticpassions ·

    Re: Axios remote access trojan (RAT)

    github.com/axios/axios/issues/

    Luckily I don't use npm much (only ) and it wasn't the malicious v1.14.1 or v0.30.4, it was v1.13.2.

    Check with `npm list axios` in your /node_modules folder. I also ran `find ~ -type d -path "*/node_modules/plain-crypto-js" 2>/dev/null` to see if the RAT is found any where on my Mac. 🤞Luckily nothing. Scary! Read the full post mortem report above!

    @paulrobertlloyd