【緊急】axiosのnmpが乗っ取られ、マルウェア版が大量出荷。何も知らないバイブコーダーさん達、大丈夫かこれ…
🚨 CRITICAL: Active supply chain attack on axios — one of npm’s most depended-on packages.
The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise.
This is textbook supply chain installer malware. axios…
— Feross (@feross) March 31, 2026





