IncidentAxios npm Package Compromised: A Two-Hour Window That Could Have Wrecked Your Pipeline
What Happened On March 31, 2026, malicious versions of the axios npm package (1.14.1 and 0.30.4) were published to the npm registry using a compromised maintainer account (@jasonsaayman). The attacker














