General
Top 10 open-source package Axios Gets Hacked
Tech Job Finder•Mar 31, 2026
In the early hours of March 31, 2026, the open-source community woke up to one of the most alarming supply-chain attacks in decades. Axios, the ubiquitous JavaScript HTTP client library downloaded more than 100 million times weekly, had been compromised on npm. Attackers hijacked the npm publishing account of lead maintainer jasonsaayman, released two poisoned versions (axios@1.14.1 and axios@0.30.4), and injected a stealthy remote access trojan (RAT) that targeted Windows, macOS, and Linux systems.

