[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-tEO5c12qOkDc9wHBvhNMyucCvBqQEc-PeLNip00IfA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"50d05853-3edb-4c11-8bd4-2f0fe413d9e9","supply-chain-attack-compromises-popular-axios-npm-package-via-stolen-credentials","35b2ebc5-b62d-463a-9792-49890f63d4eb","Supply Chain Attack Compromises Popular Axios npm Package via Stolen Credentials","A threat actor successfully compromised the widely-used Axios HTTP client library by stealing maintainer credentials and injecting platform-specific ZshBucket malware variants. This attack demonstrates how compromised developer accounts can be weaponized to distribute malware through trusted software packages to millions of downstream users. Supply chain attacks like this are particularly dangerous because they exploit the inherent trust organizations place in legitimate software libraries, making detection extremely difficult until the malicious code is already deployed across countless systems.","**Immediate actions:**\n- Audit all systems using Axios npm package and check for compromise indicators\n- Implement emergency package version rollback procedures for affected applications\n- Enable multi-factor authentication on all package manager and repository accounts\n\n**Long-term improvements:**\n- Establish software bill of materials (SBOM) tracking for all third-party dependencies\n- Deploy automated dependency scanning tools to detect suspicious package updates\n- Implement code signing verification for critical software components\n\n**Supply chain security measures:**\n- Create vendor security assessment processes for all software dependencies\n- Establish isolation environments for testing new package versions before production deployment\n- Develop incident response procedures specifically for supply chain compromises",[12,13,14,15,16],"CIS Control 2","CIS Control 16","NIST SP 800-161","NIST AC-2","NIST SI-7","published","2026-04-01T22:07:22.636356+00:00","2026-04-01T22:07:22.54+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fx.com\u002FCrowdStrike\u002Fstatus\u002F2039462812674601034","breaking-on-march-31-2026-a-threat-actor-used-stolen-maintainer-credentials-to-c","🚨 Breaking: On March 31, 2026, a threat actor used stolen maintainer credentials to compromise t...",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"771563a7-1ef7-4406-b91d-e8ce9b6ef16c","2026-04-02","morning","ThreatNoir Morning Brief — April 2","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-02\u002Fthreatnoir-morning-brief-2026-04-02.mp3"]