[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feXENkxueXst6CNLcMlcgIbMh2A5VBUY7enAgLYBuW5I":3},{"article":4,"iocs":37,"watch_terms":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"35b2ebc5-b62d-463a-9792-49890f63d4eb","🚨 Breaking: On March 31, 2026, a threat actor used stolen maintainer credentials to compromise t...","breaking-on-march-31-2026-a-threat-actor-used-stolen-maintainer-credentials-to-c","🚨 Breaking: On March 31, 2026, a threat actor used stolen maintainer credentials to compromise the widely used HTTP client library Axios Node Package Manager (npm) package and deploy platform-specific ZshBucket variants. \n\nCrowdStrike Counter Adversary Operations attributes this https:\u002F\u002Ft.co\u002FGyYwuWWSlu","On March 31, 2026, a threat actor gained access to the Axios npm package using stolen maintainer credentials and deployed platform-specific ZshBucket malware variants. CrowdStrike's Counter Adversary Operations team attributed the attack. This represents a critical supply chain compromise affecting a widely-used HTTP client library with millions of downloads.","Threat actor compromises Axios npm package with stolen credentials, deploys ZshBucket malware.",null,"https:\u002F\u002Fx.com\u002FCrowdStrike\u002Fstatus\u002F2039462812674601034","2026-04-01T22:00:00+00:00","2026-04-01T22:00:14.578424+00:00",9,[],"26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":17,"icon":11,"name":19,"slug":20},"Supply Chain","supply-chain",[22,27,32],{"category":23},{"id":24,"icon":11,"name":25,"slug":26},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":28},{"id":29,"icon":11,"name":30,"slug":31},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[38,41],{"type":26,"value":39,"context":40},"ZshBucket","Platform-specific malware variant deployed via compromised Axios npm package",{"type":26,"value":42,"context":43},"Axios","Compromised npm package used as distribution vector",[]]