PANews reported on March 31 that, according to Cointelegraph, Socket detected an active supply chain attack on version 1.14.1 of the npm core package axios. Attackers injected malicious code into axios by injecting a malicious dependency package that appeared for the first time today. Developers using axios are advised to immediately fix the version and review their project lock files.


