On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
Axios 1.14.1 and 0.30.4 injected malicious plain-crypto-js@4.2.1 after npm compromise on March 31, 2026, deploying ...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
A North Korea-nexus threat actor compromised the widely used axios npm package, delivering a cross-platform remote access ...
Google links Axios npm supply chain attack to UNC1069 after trojanized versions 1.14.1 and 0.30.4 spread WAVESHAPER.V2, ...
The maintainer account for the axios package on npm was compromised to inject a remote access trojan for Windows, macOS, and ...
Some classics deserve to be retired.
OpenClaw's Node for VS Code extension proved it can support a real local file-based workflow, but on Windows the experience still feels more like early infrastructure than finished tooling.
An attacker compromised the npm account of a lead Axios maintainer on March 30, and used it to publish two malicious versions ...
VRM MCP Proxy VRM Agent Host (vrmah) と VOICEVOX を MCP (Model Context Protocol) 経由で制御する統合プロキシサーバー。 主に Claude Code CLI / VSCode 拡張 / Codex CLI のいずれの環境でも同一の mcp_server.py で動作します。
Scripts # Development npm run dev # Start development environment npm run build # Build all modules npm run test# Run all tests npm run lint # Run linting npm run type-check # Type checking# Docker ...
Two versions of the widely used JavaScript library axios were maliciously published on npm on March 31, 2026. A hijacked ...