







Post Mortem: axios npm supply chain compromise Date: March 31, 2026 Author: Jason Saayman Status: Remediation in progress On March 31, 2026, two malicious versions of axios (1.14.1 and 0.30.4) were...
The Axios supply chain attack used individually targeted social engineering
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …
The Axios supply chain attack used individually targeted social engineering
The Axios team have published a full postmortem on the supply chain attack which resulted in a malware dependency going out in a release the other day, and it involved …
The secure way to release an npm package in 2026—Martian Chronicles, Evil Martians’ team blog
How to protect your npm package from being stolen in a supply chain attack and improve its position in security ratings

keyv and cacheable npm Package Hijacked in Supply Chain Attack | Wiz Blog
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.

Security Update: Suspected Supply Chain Incident | liteLLM
As of 2:00 PM ET on March 24, 2026

Inside the keyv npm Supply Chain Compromise | Snyk
The keyv npm compromise used preinstall malware, trusted provenance, and IDE hooks to target developer and CI credentials. Learn how to detect and respond.

Download pumping: New npm deception technique for supply chain attacks
Learn how attackers exploit automated bot traffic as part of software supply chain attacks to artificially inflate download counters and mask malicious payloads as legitimate.

npm Worm Poisons keyv, cacheable and 400+ Other Packages Across Twelve Organisations
A worm moved one byte-identical credential stealer through more than 400 npm packages in twelve organisations on 4 August 2026, including @ornikar, @deliveroo, @servicetitan, @qlik, Picsart and the keyv and cacheable family. latest still resolves to a poisoned version on most affected names, and the payload installs a dead-man switch that fires when the stolen GitHub token is revoked, so rotating credentials first triggers it.

Critical Security Vulnerability in React Server Components
Discuss @tom.sherman.is's post on Frontpage.
No more tokens! Locking down npm Publish Workflows—zachleat.com
A post by Zach Leatherman (zachleat)
What Liberal Media? Axios Thinks Being Neutral Means Kissing Trump’s Ass
The news org Axios launched in 2017, just as the first Trump administration began, created by some ex-Politico folks, claiming that they would be “an antidote to this madness” and talking about how…

OpenAI Rewrites Contract, Anthropic Returns to Negotiate—The Chaos Continues
In less than a week, the Pentagon blacklisted an AI company for having ethics, declared it a supply chain risk, watched its preferred replacement face a massive user revolt, and then sat down to am…

Dependency cooldowns turn you into a free-rider
Against dependency cooldowns as a response to supply chain attacks

Mercor on Twitter / X
The privacy and security of our customers and contractors is foundational to everything we do at Mercor. We recently identified that we were one of thousands of companies impacted by a supply chain attack involving LiteLLM.Our security team moved promptly to contain and…— Mercor (@mercor_ai) March 31, 2026