The maintainer account for the axios package on npm was compromised to inject a remote access trojan for Windows, macOS, and ...
Attackers stole a long-lived npm token from the lead axios maintainer and published two poisoned versions that drop a ...
Anthropic is scrambling to contain the leak, but the AI coding agent is spreading far and wide and being picked apart.