• Blog
  • About
  • Courses
  • Help
  • Português PT
Home » Tags
tags

Postinstall

post

The Axios case: what a compromised package teaches about trusting npm

On March 31, 2026, between 00:21 UTC and roughly 03:15 UTC, two versions of axios sat on the npm registry with an extra dependency declared in package.json: plain-crypto-js@4.2.1. That dependency was never imported at …

17 Apr 2026 · 7 min · Diego Rodrigo
Read post

Copyright © 2022-2026 Diego Rodrigo. All rights reserved.

Privacy policy Cookies Terms of use