
A significant security breach has emerged as a hacker managed to infiltrate and alter a widely-used open-source development tool, endangering millions of developers worldwide. On Monday, malicious versions of the popular JavaScript library Axios were uploaded, which developers utilize to enable internet connectivity in their software. This library, hosted on npm—a repository for open-source code—boasts tens of millions of downloads each week. The intrusion was detected and mitigated within approximately three hours, as reported by the cybersecurity firm StepSecurity, which investigated the incident. This alarming incident is part of a larger trend where cybercriminals are increasingly targeting developers of renowned open-source projects. By compromising such essential tools, hackers can potentially exploit vast networks of users who rely on the tainted code. Known as supply chain attacks, these breaches exploit software vulnerabilities to enable hackers to infiltrate systems of anyone who has downloaded the compromised software. Over the past few years, notable victims of similar attacks include major firms like 3CX, Kaseya, and SolarWinds, alongside open-source projects like Log4j and Polyfill.io. While the full extent of the damage remains unclear, security experts from Aikido, who also analyzed the breach, advise anyone who downloaded the altered version of Axios to consider their systems compromised. The hacker gained access by taking control of an account belonging to one of the primary developers, replacing the legitimate email address with their own. This manipulation made it significantly harder for the legitimate developer to reclaim their account. Once the hacker secured control, they injected malicious code designed to deploy a remote access trojan (RAT), granting them extensive control over the victim's computer. The attacker then released seemingly legitimate updates for Windows, macOS, and Linux users. To further obfuscate their actions, the malware was crafted to self-delete after installation, evading detection from anti-malware tools and investigators, according to security researchers.
In an impressive leap forward, Blinkit has significantly increased its operational scale, with the cost to establish a s...
Business Today | Jul 24, 2026, 09:35
OpenAI has unveiled an exciting update for its ChatGPT desktop application, introducing a voice control feature that ena...
TechCrunch | Jul 24, 2026, 14:00
Good morning and happy Friday! As the weekend approaches, whether you're catching a play or diving into video games, it’...
CNBC | Jul 24, 2026, 12:25
In a bold move to enhance user engagement, Jeff Bezos is spearheading a significant redesign of Prime Video, emphasizing...
Business Today | Jul 24, 2026, 10:55
A coalition of major technology companies, including Nvidia, Microsoft, Meta, and Palantir, has issued a call to action ...
CNBC | Jul 24, 2026, 14:30