StepSecurity identified malicious versions of the axios HTTP client library published to npm, axios@1.14.1 and axios@0.30.4, which inject a remote access trojan (RAT) dropper. Developers who installed these versions should rotate all secrets and credentials, check network logs, and downgrade to safe versions, and StepSecurity provides end-to-end npm supply chain security across three pillars: ...