On March 30-31, 2026, threat actors published two malicious versions of the popular HTTP library axios (versions 1.14.1 and 0.30.4) to the npm registry. Both versions included a new dependency named plain-crypto-js which, in its 4.2.1 release, contained a fully-featured cross-platform dropper that silently installed a Remote Access Trojan (RAT) on developer machines. The pack...
Click on the "Follow" button below and you'll get the latest news from Mend Leadership Update: Building on Our Momentum for the Next Phase of Growth via email, mobile or you can read them on your personal news page on this site.
You can unsubscribe anytime you want easily.
You can also choose the topics or keywords that you're interested in, so you receive only what you want.
Mend Leadership Update: Building on Our Momentum for the Next Phase of Growth title: Mend.io Resource Center