Axios NPM Package Breached in North Korean Supply Chain Attack

A long-lived NPM access token was used to bypass the GitHub Actions OIDC-based CI/CD publishing workflow and push backdoored package versions.

The post Axios NPM Package Breached in North Korean Supply Chain Attack appeared first on SecurityWeek.

This article has been indexed from SecurityWeek

Read the original article: